|
197361
|
4.3 |
MEDIUM
Network
|
ibm
|
cloud_pak_for_security
|
IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session. IBM X-Force ID: 18…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-4696
|
2024-11-21 14:33 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197362
|
9.0 |
CRITICAL
Network
|
ibm
|
cloud_pak_for_security
|
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents.…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-4627
|
2024-11-21 14:33 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197363
|
4.3 |
MEDIUM
Network
|
ibm
|
cloud_pak_for_security
|
IBM Cloud Pak for Security 1.3.0.1 (CP4S) could reveal sensitive information about the internal network to an authenticated user using a specially crafted HTTP request. IBM X-Force ID: 185362.
|
NVD-CWE-noinfo
|
CVE-2020-4626
|
2024-11-21 14:33 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197364
|
5.3 |
MEDIUM
Network
|
ibm
|
cloud_pak_for_security
|
IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerabil…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-4625
|
2024-11-21 14:33 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197365
|
5.3 |
MEDIUM
Network
|
ibm
|
cloud_pak_for_security
|
IBM Cloud Pak for Security 1.3.0.1 (CP4S) uses weaker than expected cryptographic algorithms during negotiation could allow an attacker to decrypt sensitive information.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4624
|
2024-11-21 14:33 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197366
|
9.8 |
CRITICAL
Network
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to e…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-4854
|
2024-11-21 14:33 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197367
|
5.9 |
MEDIUM
Network
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker cou…
|
CWE-862
Missing Authorization
|
CVE-2020-4783
|
2024-11-21 14:33 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197368
|
5.3 |
MEDIUM
Network
|
ibm
|
spectrum_protect_operations_center
|
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a webs…
|
CWE-287
Improper Authentication
|
CVE-2020-4771
|
2024-11-21 14:33 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197369
|
7.5 |
HIGH
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-For…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4937
|
2024-11-21 14:33 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197370
|
7.8 |
HIGH
Local
|
ibm
|
db2
|
IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to exe…
|
CWE-426
Untrusted Search Path
|
CVE-2020-4739
|
2024-11-21 14:33 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|