|
197381
|
8.8 |
HIGH
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which c…
|
CWE-89
SQL Injection
|
CVE-2020-4655
|
2024-11-21 14:33 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197382
|
8.8 |
HIGH
Network
|
ibm
|
sterling_file_gateway
|
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta…
|
CWE-89
SQL Injection
|
CVE-2020-4647
|
2024-11-21 14:33 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197383
|
3.3 |
LOW
Local
|
ibm
|
infosphere_information_server
|
IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system. IBM X-Force ID: 190910.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-4886
|
2024-11-21 14:33 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197384
|
7.2 |
HIGH
Network
|
ibm
|
cognos_controller
|
A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to the server where the application is installed, can escalate their privilege from …
|
NVD-CWE-noinfo
|
CVE-2020-4685
|
2024-11-21 14:33 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197385
|
5.4 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4760
|
2024-11-21 14:33 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197386
|
5.4 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pot…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4704
|
2024-11-21 14:33 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197387
|
7.8 |
HIGH
Local
|
ibm
|
filenet_content_manager
|
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file con…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-4759
|
2024-11-21 14:33 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197388
|
4.8 |
MEDIUM
Adjacent
|
ibm
|
maximo_spatial_asset_management
|
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tran…
|
CWE-352
Origin Validation Error
|
CVE-2020-4651
|
2024-11-21 14:33 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197389
|
3.3 |
LOW
Local
|
ibm
|
maximo_spatial_asset_management
|
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-4650
|
2024-11-21 14:33 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197390
|
5.4 |
MEDIUM
Network
|
ibm
|
app_connect_enterprise_certified_container
|
IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malic…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-4785
|
2024-11-21 14:33 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|