|
197471
|
7.8 |
HIGH
Local
|
ibm
|
i2_analysts_notebook
|
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file,…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-4262
|
2024-11-21 14:32 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197472
|
7.8 |
HIGH
Local
|
ibm
|
i2_analysts_notebook
|
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file,…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-4261
|
2024-11-21 14:32 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197473
|
6.5 |
MEDIUM
Network
|
ibm
|
sterling_file_gateway
|
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorize…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-4259
|
2024-11-21 14:32 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197474
|
7.8 |
HIGH
Local
|
ibm
|
i2_analysts_notebook
|
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file,…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-4258
|
2024-11-21 14:32 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197475
|
7.8 |
HIGH
Local
|
ibm
|
i2_analysts_notebook
|
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file,…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-4257
|
2024-11-21 14:32 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197476
|
4.3 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 trough 6.0.3.1 could allow an authenticated user to obtain sensitive information from a cached web page. IBM X-Force ID: 177089.
|
NVD-CWE-noinfo
|
CVE-2020-4312
|
2024-11-21 14:32 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197477
|
5.3 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect's V2018.4.1.0 through 2018.4.1.10 management server has an unsecured api which can be exploited by an unauthenticated attacker to obtain sensitive information. IBM X-Force ID: 178322.
|
NVD-CWE-noinfo
|
CVE-2020-4346
|
2024-11-21 14:32 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197478
|
5.4 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker coul…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-4195
|
2024-11-21 14:32 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197479
|
4.3 |
MEDIUM
Network
|
ibm
|
data_risk_manager
|
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to downl…
|
CWE-22
Path Traversal
|
CVE-2020-4430
|
2024-11-21 14:32 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197480
|
9.8 |
CRITICAL
Network
|
ibm
|
data_risk_manager
|
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and exec…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-4429
|
2024-11-21 14:32 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|