|
219771
|
6.5 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote att…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2019-4471
|
2024-11-21 13:43 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219772
|
7.8 |
HIGH
Local
|
ibm
|
db2
|
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-4588
|
2024-11-21 13:43 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219773
|
5.3 |
MEDIUM
Network
|
ibm
|
security_guardium_data_encrpytion
|
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-4687
|
2024-11-21 13:43 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219774
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium_data_encrpytion
|
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-4160
|
2024-11-21 13:43 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219775
|
3.5 |
LOW
Physics
|
ibm
|
maximo_anywhere
|
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprecated operating system version that could compromised the confidentiality and integrity of the servi…
|
CWE-200
Information Exposure
|
CVE-2019-4349
|
2024-11-21 13:43 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219776
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or…
|
CWE-384
Session Fixation
|
CVE-2019-4563
|
2024-11-21 13:43 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219777
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 165949.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-4547
|
2024-11-21 13:43 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219778
|
8.8 |
HIGH
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to v…
|
CWE-89
SQL Injection
|
CVE-2019-4680
|
2024-11-21 13:43 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219779
|
6.1 |
MEDIUM
Network
|
ibm
|
security_verify_access security_access_manager
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted U…
|
NVD-CWE-Other
|
CVE-2019-4552
|
2024-11-21 13:43 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219780
|
7.5 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.
|
NVD-CWE-noinfo
|
CVE-2019-4545
|
2024-11-21 13:43 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|