|
197331
|
5.5 |
MEDIUM
Local
|
ibm
|
security_key_lifecycle_manager
|
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184157.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-4568
|
2024-11-21 14:32 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197332
|
4.3 |
MEDIUM
Network
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive information to an authenticated user that could be used in further attacks against the system. IBM X-Force I…
|
NVD-CWE-noinfo
|
CVE-2020-4484
|
2024-11-21 14:32 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197333
|
4.3 |
MEDIUM
Network
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. Thi…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4483
|
2024-11-21 14:32 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197334
|
6.5 |
MEDIUM
Network
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow an authenticated user to bypass security. A user with access to a snapshot could apply unauthorized additional statuses v…
|
NVD-CWE-noinfo
|
CVE-2020-4482
|
2024-11-21 14:32 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197335
|
6.8 |
MEDIUM
Physics
|
hcltech
|
notes
|
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input pa…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-4097
|
2024-11-21 14:32 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197336
|
7.8 |
HIGH
Local
|
ibm
|
i2_ibase
|
IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-4588
|
2024-11-21 14:32 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197337
|
7.5 |
HIGH
Network
|
ibm
|
i2_ibase
|
IBM i2 iBase 8.9.13 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4584
|
2024-11-21 14:32 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197338
|
6.5 |
MEDIUM
Network
|
vmware
|
horizon_client
|
VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges on the machine where Horizon Client for Windows is …
|
NVD-CWE-noinfo
|
CVE-2020-3998
|
2024-11-21 14:32 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197339
|
5.4 |
MEDIUM
Network
|
vmware
|
horizon
|
VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which…
|
CWE-79
Cross-site Scripting
|
CVE-2020-3997
|
2024-11-21 14:32 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197340
|
5.5 |
MEDIUM
Local
|
vmware
|
velero
|
Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorized users.
|
NVD-CWE-noinfo
|
CVE-2020-3996
|
2024-11-21 14:32 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|