|
219031
|
4.3 |
MEDIUM
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences …
|
CWE-22
Path Traversal
|
CVE-2019-4582
|
2024-11-21 13:43 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219032
|
4.3 |
MEDIUM
Network
|
ibm
|
cognos_analytics
|
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.
|
CWE-269
Improper Privilege Management
|
CVE-2019-4589
|
2024-11-21 13:43 |
2020-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219033
|
5.3 |
MEDIUM
Network
|
ibm
|
cognos_analytics
|
IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser data. IBM X-Force ID: 161748.
|
NVD-CWE-noinfo
|
CVE-2019-4366
|
2024-11-21 13:43 |
2020-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219034
|
5.4 |
MEDIUM
Network
|
hcltech
|
marketing_campaign
|
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious …
|
CWE-79
Cross-site Scripting
|
CVE-2019-4091
|
2024-11-21 13:43 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219035
|
5.4 |
MEDIUM
Network
|
hcltech
|
marketing_campaign
|
"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."
|
CWE-79
Cross-site Scripting
|
CVE-2019-4090
|
2024-11-21 13:43 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219036
|
7.8 |
HIGH
Local
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.
|
CWE-384
Session Fixation
|
CVE-2019-4591
|
2024-11-21 13:43 |
2020-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219037
|
6.1 |
MEDIUM
Network
|
hcltech
|
appscan
|
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
|
CWE-79
Cross-site Scripting
|
CVE-2019-4324
|
2024-11-21 13:43 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219038
|
4.3 |
MEDIUM
Network
|
hcltech
|
appscan
|
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-4323
|
2024-11-21 13:43 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219039
|
7.8 |
HIGH
Local
|
ibm
|
security_identity_manager_virtual_appliance
|
IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171512.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-4676
|
2024-11-21 13:43 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219040
|
6.3 |
MEDIUM
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete inform…
|
CWE-89
SQL Injection
|
CVE-2019-4650
|
2024-11-21 13:43 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|