|
197661
|
4.4 |
MEDIUM
Local
|
ibm
|
security_verify_privilege_manager
|
IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensiti…
|
CWE-611
XXE
|
CVE-2020-4606
|
2024-11-21 14:32 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197662
|
5.3 |
MEDIUM
Network
|
ibm
|
websphere_extreme_scale
|
IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer hea…
|
CWE-200
Information Exposure
|
CVE-2020-4336
|
2024-11-21 14:32 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197663
|
5.4 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager
|
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.
|
CWE-384
Session Fixation
|
CVE-2020-4555
|
2024-11-21 14:32 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197664
|
6.5 |
MEDIUM
Local
|
vmware
|
workstation esxi fusion
|
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundatio…
|
CWE-20
Improper Input Validation
|
CVE-2020-3999
|
2024-11-21 14:32 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197665
|
6.1 |
MEDIUM
Network
|
hcltech
|
domino
|
HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerabil…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4080
|
2024-11-21 14:32 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197666
|
3.6 |
LOW
Local
|
vmware
|
carbon_black_cloud
|
The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sens…
|
NVD-CWE-noinfo
|
CVE-2020-4008
|
2024-11-21 14:32 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197667
|
6.7 |
MEDIUM
Local
|
hcltech
|
notes
|
HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Notes or execute attacker-controlle…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-4102
|
2024-11-21 14:32 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197668
|
5.3 |
MEDIUM
Network
|
hcltech
|
domino
|
HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault…
|
NVD-CWE-noinfo
|
CVE-2020-4128
|
2024-11-21 14:32 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197669
|
5.3 |
MEDIUM
Network
|
hcltech
|
hcl_domino
|
HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the LDAP service…
|
NVD-CWE-noinfo
|
CVE-2020-4129
|
2024-11-21 14:32 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197670
|
5.9 |
MEDIUM
Network
|
hcltech
|
hcl_inotes
|
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-4126
|
2024-11-21 14:32 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|