|
194661
|
8.1 |
HIGH
Network
|
ibm
|
jazz_for_service_management tivoli_netcool\/omnibus_gui
|
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit th…
|
CWE-611
XXE
|
CVE-2021-29831
|
2024-11-21 15:01 |
2021-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194662
|
6.0 |
MEDIUM
Local
|
ibm
|
powervm_hypervisor
|
IBM PowerVM Hypervisor FW860, FW930, FW940, and FW950 could allow a local user to create a specially crafted sequence of hypervisor calls from a partition that could crash the system. IBM X-Force ID:…
|
CWE-74
Injection
|
CVE-2021-29795
|
2024-11-21 15:01 |
2021-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194663
|
6.5 |
MEDIUM
Network
|
ibm
|
tivoli_netcool\/omnibus_webgui
|
IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticated usre to cause a denial of service through the WebGUI Map Creation page. IBM X-Force ID: 205685.
|
NVD-CWE-noinfo
|
CVE-2021-29856
|
2024-11-21 15:01 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194664
|
5.4 |
MEDIUM
Network
|
ibm
|
tivoli_netcool\/omnibus_webgui
|
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29821
|
2024-11-21 15:01 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194665
|
5.4 |
MEDIUM
Network
|
ibm
|
tivoli_netcool\/omnibus_webgui
|
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29820
|
2024-11-21 15:01 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194666
|
5.4 |
MEDIUM
Network
|
ibm
|
tivoli_netcool\/omnibus_webgui
|
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29819
|
2024-11-21 15:01 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194667
|
5.4 |
MEDIUM
Network
|
ibm
|
tivoli_netcool\/omnibus_webgui
|
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29818
|
2024-11-21 15:01 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194668
|
5.4 |
MEDIUM
Network
|
ibm
|
tivoli_netcool\/omnibus_webgui
|
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29817
|
2024-11-21 15:01 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194669
|
4.9 |
MEDIUM
Network
|
ibm
|
tivoli_netcool\/omnibus_webgui
|
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in plain clear text which can be read by an authenticated admin user. IBM X-Force ID: 204329.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-29811
|
2024-11-21 15:01 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194670
|
5.4 |
MEDIUM
Network
|
ibm
|
tivoli_netcool\/omnibus_webgui
|
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29809
|
2024-11-21 15:01 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|