|
198361
|
8.1 |
HIGH
Network
|
ibm
|
db2
|
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-4945
|
2024-11-21 14:33 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198362
|
4.7 |
MEDIUM
Local
|
ibm
|
db2
|
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the configuration of Db2 due to a race condition of a symbolic link,. IBM X-Force …
|
CWE-59
Link Following
|
CVE-2020-4885
|
2024-11-21 14:33 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198363
|
5.4 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager
|
IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intende…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5000
|
2024-11-21 14:33 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198364
|
9.1 |
CRITICAL
Network
|
ibm
|
financial_transaction_manager
|
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive…
|
CWE-611
XXE
|
CVE-2020-5003
|
2024-11-21 14:33 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198365
|
5.3 |
MEDIUM
Network
|
ibm
|
datapower_gateway
|
IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized part…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-5008
|
2024-11-21 14:33 |
2021-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198366
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_doors_next_generation rational_quality_manager collaborative_lifecycle_management engineering_test_management rational_engineering_lifecycle_manager engineering_lifecycle_mana…
|
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fu…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5030
|
2024-11-21 14:33 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198367
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_doors_next_generation rational_quality_manager collaborative_lifecycle_management engineering_test_management rational_engineering_lifecycle_manager engineering_lifecycle_mana…
|
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4977
|
2024-11-21 14:33 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198368
|
6.5 |
MEDIUM
Network
|
ibm
|
rational_doors_next_generation rational_quality_manager collaborative_lifecycle_management engineering_test_management rational_engineering_lifecycle_manager engineering_lifecycle_mana…
|
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.
|
NVD-CWE-noinfo
|
CVE-2020-4732
|
2024-11-21 14:33 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198369
|
4.9 |
MEDIUM
Network
|
ibm
|
8335-gca_firmware 8335-gta_firmware 8335-gtb_firmware
|
IBM Host firmware for LC-class Systems is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A remote privileged attacker could exploit this vulnerability and cause a de…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-4839
|
2024-11-21 14:33 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198370
|
8.8 |
HIGH
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in …
|
CWE-89
SQL Injection
|
CVE-2020-4990
|
2024-11-21 14:33 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|