|
198061
|
3.3 |
LOW
Local
|
ibm
|
tivoli_business_service_manager
|
IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-4344
|
2024-11-21 14:32 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198062
|
5.4 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4578
|
2024-11-21 14:32 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198063
|
5.4 |
MEDIUM
Network
|
ibm
|
business_automation_workflow business_process_manager
|
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4516
|
2024-11-21 14:32 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198064
|
7.8 |
HIGH
Local
|
ibm
|
aspera_connect
|
IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to o…
|
CWE-426
Untrusted Search Path
|
CVE-2020-4545
|
2024-11-21 14:32 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198065
|
6.5 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs. IBM X-Force …
|
NVD-CWE-noinfo
|
CVE-2020-4337
|
2024-11-21 14:32 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198066
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_collaborative_lifecycle_management rational_doors_next_generation rational_engineering_lifecycle_manager doors_next engineeri…
|
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4546
|
2024-11-21 14:32 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198067
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_collaborative_lifecycle_management rational_doors_next_generation rational_engineering_lifecycle_manager doors_next engineeri…
|
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4522
|
2024-11-21 14:32 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198068
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_collaborative_lifecycle_management rational_doors_next_generation rational_engineering_lifecycle_manager doors_next engineeri…
|
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4445
|
2024-11-21 14:32 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198069
|
5.5 |
MEDIUM
Local
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device w…
|
CWE-88
Argument Injection
|
CVE-2020-4492
|
2024-11-21 14:32 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198070
|
3.3 |
LOW
Local
|
ibm
|
spectrum_protect_server
|
IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted c…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-4591
|
2024-11-21 14:32 |
2020-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|