|
197681
|
5.3 |
MEDIUM
Network
|
ibm
|
cloud_pak_for_security
|
IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerabil…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-4625
|
2024-11-21 14:33 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197682
|
5.3 |
MEDIUM
Network
|
ibm
|
cloud_pak_for_security
|
IBM Cloud Pak for Security 1.3.0.1 (CP4S) uses weaker than expected cryptographic algorithms during negotiation could allow an attacker to decrypt sensitive information.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4624
|
2024-11-21 14:33 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197683
|
9.8 |
CRITICAL
Network
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to e…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-4854
|
2024-11-21 14:33 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197684
|
5.9 |
MEDIUM
Network
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker cou…
|
CWE-862
Missing Authorization
|
CVE-2020-4783
|
2024-11-21 14:33 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197685
|
5.3 |
MEDIUM
Network
|
ibm
|
spectrum_protect_operations_center
|
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a webs…
|
CWE-287
Improper Authentication
|
CVE-2020-4771
|
2024-11-21 14:33 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197686
|
7.5 |
HIGH
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-For…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4937
|
2024-11-21 14:33 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197687
|
7.8 |
HIGH
Local
|
ibm
|
db2
|
IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to exe…
|
CWE-426
Untrusted Search Path
|
CVE-2020-4739
|
2024-11-21 14:33 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197688
|
4.7 |
MEDIUM
Local
|
ibm fedoraproject oracle
|
vios aix fedora communications_cloud_native_core_binding_support_function communications_cloud_native_core_policy communications_cloud_native_core_network_exposure_function
|
IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
|
NVD-CWE-noinfo
|
CVE-2020-4788
|
2024-11-21 14:33 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197689
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …
|
CWE-79
Cross-site Scripting
|
CVE-2020-4718
|
2024-11-21 14:33 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197690
|
7.8 |
HIGH
Local
|
ibm
|
db2
|
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to exe…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-4701
|
2024-11-21 14:33 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|