|
219031
|
7.5 |
HIGH
Network
|
ibm
|
cloud_cli
|
IBM Cloud CLI 0.6.0 through 0.16.1 windows installers are signed using SHA1 certificate. An attacker might be able to exploit the weak algorithm to generate a installer with malicious software inside…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-4427
|
2024-11-21 13:43 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219032
|
6.5 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper data representation. IBM X-Force ID: 171319.
|
NVD-CWE-noinfo
|
CVE-2019-4670
|
2024-11-21 13:43 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219033
|
3.5 |
LOW
Adjacent
|
ibm
|
cloud_automation_manager
|
IBM Cloud Automation Manager 3.2.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user o…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2019-4616
|
2024-11-21 13:43 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219034
|
8.8 |
HIGH
Network
|
ibm
|
planning_analytics
|
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM…
|
CWE-352
Origin Validation Error
|
CVE-2019-4613
|
2024-11-21 13:43 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219035
|
9.8 |
CRITICAL
Network
|
ibm
|
security_identity_manager
|
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external comp…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-4675
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219036
|
4.9 |
MEDIUM
Network
|
ibm
|
security_identity_manager
|
IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) t…
|
CWE-22
Path Traversal
|
CVE-2019-4674
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219037
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or br…
|
CWE-200
Information Exposure
|
CVE-2019-4562
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219038
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 165953.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-4551
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219039
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.
|
NVD-CWE-noinfo
|
CVE-2019-4550
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219040
|
6.1 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit th…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-4548
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|