|
219181
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 165953.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-4551
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219182
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.
|
NVD-CWE-noinfo
|
CVE-2019-4550
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219183
|
6.1 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit th…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-4548
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219184
|
7.2 |
HIGH
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity…
|
NVD-CWE-noinfo
|
CVE-2019-4541
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219185
|
7.5 |
HIGH
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-4540
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219186
|
5.4 |
MEDIUM
Network
|
ibm
|
security_identity_manager
|
IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4451
|
2024-11-21 13:43 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219187
|
4.3 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and version that could be used in further attacks against the system. IBM X-Force …
|
NVD-CWE-noinfo
|
CVE-2019-4679
|
2024-11-21 13:43 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219188
|
7.5 |
HIGH
Network
|
ibm
|
security_secret_server
|
IBM Security Secret Server 10.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 170045.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-4639
|
2024-11-21 13:43 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219189
|
3.7 |
LOW
Network
|
ibm
|
security_secret_server
|
IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle tech…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2019-4638
|
2024-11-21 13:43 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219190
|
4.3 |
MEDIUM
Network
|
ibm
|
security_secret_server
|
IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IB…
|
NVD-CWE-Other
|
CVE-2019-4637
|
2024-11-21 13:43 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|