|
222381
|
8.8 |
HIGH
Network
|
ibm
|
pureapplication_system
|
IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify o…
|
CWE-89
SQL Injection
|
CVE-2019-4224
|
2024-11-21 13:43 |
2019-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222382
|
5.3 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive information about the system users using specially crafted HTTP requests. IBM X-Force ID: 162162.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-4382
|
2024-11-21 13:43 |
2019-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222383
|
4.3 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-4377
|
2024-11-21 13:43 |
2019-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222384
|
5.4 |
MEDIUM
Network
|
ibm
|
security_access_manager
|
IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors. IBM X-Force ID: 158…
|
CWE-862
Missing Authorization
|
CVE-2019-4158
|
2024-11-21 13:43 |
2019-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222385
|
6.1 |
MEDIUM
Network
|
ibm
|
security_access_manager
|
IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended func…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4157
|
2024-11-21 13:43 |
2019-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222386
|
5.9 |
MEDIUM
Network
|
ibm
|
security_access_manager
|
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158572.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-4156
|
2024-11-21 13:43 |
2019-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222387
|
6.8 |
MEDIUM
Network
|
ibm
|
security_access_manager
|
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site,…
|
CWE-601
Open Redirect
|
CVE-2019-4153
|
2024-11-21 13:43 |
2019-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222388
|
4.4 |
MEDIUM
Local
|
ibm
|
security_access_manager
|
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a clos…
|
CWE-384
Session Fixation
|
CVE-2019-4152
|
2024-11-21 13:43 |
2019-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222389
|
5.9 |
MEDIUM
Network
|
ibm
|
security_access_manager
|
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158512.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-4151
|
2024-11-21 13:43 |
2019-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222390
|
3.7 |
LOW
Network
|
ibm
|
security_access_manager
|
IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) …
|
CWE-295
Improper Certificate Validation
|
CVE-2019-4150
|
2024-11-21 13:43 |
2019-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|