|
195721
|
9.1 |
CRITICAL
Network
|
ibm
|
power9_system_firmware scale-out_lc_system_firmware
|
IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2021-20487
|
2024-11-21 14:46 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195722
|
6.5 |
MEDIUM
Network
|
ibm
|
cloud_pak_for_data
|
IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.
|
NVD-CWE-noinfo
|
CVE-2021-20486
|
2024-11-21 14:46 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195723
|
5.5 |
MEDIUM
Local
|
redhat fedoraproject
|
ansible_tower ansible fedora
|
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw…
|
-
|
CVE-2021-20178
|
2024-11-21 14:46 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195724
|
7.5 |
HIGH
Network
|
privoxy
|
privoxy
|
A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-20209
|
2024-11-21 14:46 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195725
|
7.2 |
HIGH
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 199184.
|
CWE-78
OS Command
|
CVE-2021-20557
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195726
|
5.3 |
MEDIUM
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further …
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-20428
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195727
|
9.8 |
CRITICAL
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, o…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-20426
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195728
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-20419
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195729
|
7.8 |
HIGH
Local
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-20389
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195730
|
6.1 |
MEDIUM
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20386
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|