|
197651
|
4.4 |
MEDIUM
Local
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-4602
|
2024-11-21 14:32 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197652
|
5.3 |
MEDIUM
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used i…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4600
|
2024-11-21 14:32 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197653
|
5.3 |
MEDIUM
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used i…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4599
|
2024-11-21 14:32 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197654
|
4.3 |
MEDIUM
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user o…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-4597
|
2024-11-21 14:32 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197655
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184812.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4596
|
2024-11-21 14:32 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197656
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184819.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4595
|
2024-11-21 14:32 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197657
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184800.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4594
|
2024-11-21 14:32 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197658
|
7.7 |
HIGH
Network
|
combodo
|
itop
|
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows gettin…
|
-
|
CVE-2020-4079
|
2024-11-21 14:32 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197659
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation rational_rhapsody_design_manager rhapsody_model_manager doors_next engineering_workflow_management c…
|
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furthe…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4544
|
2024-11-21 14:32 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197660
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation rational_rhapsody_design_manager rhapsody_model_manager doors_next engineering_workflow_management c…
|
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furthe…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4487
|
2024-11-21 14:32 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|