|
219021
|
8.8 |
HIGH
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to v…
|
CWE-89
SQL Injection
|
CVE-2019-4680
|
2024-11-21 13:43 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219022
|
6.1 |
MEDIUM
Network
|
ibm
|
security_verify_access security_access_manager
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted U…
|
NVD-CWE-Other
|
CVE-2019-4552
|
2024-11-21 13:43 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219023
|
7.5 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.
|
NVD-CWE-noinfo
|
CVE-2019-4545
|
2024-11-21 13:43 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219024
|
7.5 |
HIGH
Network
|
hcltech
|
appscan
|
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2019-4326
|
2024-11-21 13:43 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219025
|
5.3 |
MEDIUM
Network
|
hcltech
|
appscan
|
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-4325
|
2024-11-21 13:43 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219026
|
6.3 |
MEDIUM
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delet…
|
CWE-89
SQL Injection
|
CVE-2019-4671
|
2024-11-21 13:43 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219027
|
4.3 |
MEDIUM
Network
|
ibm
|
resilient_security_orchestration_automation_and_response
|
IBM Resilient SOAR 38 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force …
|
NVD-CWE-Other
|
CVE-2019-4579
|
2024-11-21 13:43 |
2020-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219028
|
4.3 |
MEDIUM
Network
|
ibm
|
resilient_security_orchestration_automation_and_response
|
IBM Resilient SOAR V38.0 users may experience a denial of service of the SOAR Platform due to a insufficient input validation. IBM X-Force ID: 165589.
|
CWE-20
Improper Input Validation
|
CVE-2019-4533
|
2024-11-21 13:43 |
2020-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219029
|
4.3 |
MEDIUM
Network
|
ibm
|
guardium_data_encryption guardium_for_cloud_key_management
|
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// l…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2019-4688
|
2024-11-21 13:43 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219030
|
5.3 |
MEDIUM
Network
|
ibm
|
guardium_data_encryption guardium_for_cloud_key_management
|
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// l…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2019-4686
|
2024-11-21 13:43 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|