|
218961
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium_data_encrpytion
|
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-4160
|
2024-11-21 13:43 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218962
|
3.5 |
LOW
Physics
|
ibm
|
maximo_anywhere
|
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprecated operating system version that could compromised the confidentiality and integrity of the servi…
|
CWE-200
Information Exposure
|
CVE-2019-4349
|
2024-11-21 13:43 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218963
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or…
|
CWE-384
Session Fixation
|
CVE-2019-4563
|
2024-11-21 13:43 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218964
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 165949.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-4547
|
2024-11-21 13:43 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218965
|
8.8 |
HIGH
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to v…
|
CWE-89
SQL Injection
|
CVE-2019-4680
|
2024-11-21 13:43 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218966
|
6.1 |
MEDIUM
Network
|
ibm
|
security_verify_access security_access_manager
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted U…
|
NVD-CWE-Other
|
CVE-2019-4552
|
2024-11-21 13:43 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218967
|
7.5 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.
|
NVD-CWE-noinfo
|
CVE-2019-4545
|
2024-11-21 13:43 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218968
|
7.5 |
HIGH
Network
|
hcltech
|
appscan
|
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2019-4326
|
2024-11-21 13:43 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218969
|
5.3 |
MEDIUM
Network
|
hcltech
|
appscan
|
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-4325
|
2024-11-21 13:43 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218970
|
6.3 |
MEDIUM
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delet…
|
CWE-89
SQL Injection
|
CVE-2019-4671
|
2024-11-21 13:43 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|