|
219531
|
5.3 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network via API swagger. IBM X-force ID: 162947.
|
CWE-200
Information Exposure
|
CVE-2019-4437
|
2024-11-21 13:43 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219532
|
8.2 |
HIGH
Network
|
ibm
|
business_process_manager business_automation_workflow
|
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could …
|
CWE-611
XXE
|
CVE-2019-4424
|
2024-11-21 13:43 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219533
|
8.2 |
HIGH
Network
|
ibm
|
security_guardium_big_data_intelligence
|
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to…
|
CWE-611
XXE
|
CVE-2019-4340
|
2024-11-21 13:43 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219534
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium_big_data_intelligence
|
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) does not properly restrict the size or amount of resources that are requested or influenced by an actor. This weakness can be used to consume …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-4338
|
2024-11-21 13:43 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219535
|
6.5 |
MEDIUM
Network
|
ibm
|
storediq
|
IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force…
|
CWE-352
Origin Validation Error
|
CVE-2019-4167
|
2024-11-21 13:43 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219536
|
5.4 |
MEDIUM
Network
|
ibm
|
cloud_private
|
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pote…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4120
|
2024-11-21 13:43 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219537
|
4.3 |
MEDIUM
Network
|
ibm
|
emptoris_sourcing emptoris_spend_analysis emptoris_contract_management
|
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive in…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-4485
|
2024-11-21 13:43 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219538
|
4.3 |
MEDIUM
Network
|
ibm
|
emptoris_sourcing emptoris_spend_analysis emptoris_contract_management
|
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive in…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-4484
|
2024-11-21 13:43 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219539
|
9.8 |
CRITICAL
Network
|
ibm
|
emptoris_spend_analysis emptoris_contract_management
|
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, whic…
|
CWE-89
SQL Injection
|
CVE-2019-4483
|
2024-11-21 13:43 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219540
|
9.8 |
CRITICAL
Network
|
ibm
|
emptoris_spend_analysis emptoris_contract_management
|
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, whic…
|
CWE-89
SQL Injection
|
CVE-2019-4481
|
2024-11-21 13:43 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|