|
219041
|
2.7 |
LOW
Network
|
ibm
|
security_identity_manager_virtual_appliance
|
IBM Security Identity Manager Virtual Appliance 7.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 172015.
|
NVD-CWE-noinfo
|
CVE-2019-4705
|
2024-11-21 13:44 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219042
|
4.3 |
MEDIUM
Network
|
ibm
|
security_identity_manager_virtual_appliance
|
IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http://…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2019-4704
|
2024-11-21 13:44 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219043
|
5.3 |
MEDIUM
Adjacent
|
huawei
|
alp-al00b_firmware alp-l09_firmware alp-l29_firmware bla-l29c_firmware berkeley-al20_firmware berkeley-l09_firmware charlotte-l09c_firmware charlotte-l29c_firmware columbia-al…
|
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insuffic…
|
CWE-20
Improper Input Validation
|
CVE-2019-5303
|
2024-11-21 13:44 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219044
|
5.3 |
MEDIUM
Adjacent
|
huawei
|
alp-al00b_firmware alp-l09_firmware alp-l29_firmware bla-l29c_firmware berkeley-al20_firmware berkeley-l09_firmware charlotte-l09c_firmware charlotte-l29c_firmware columbia-al…
|
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insuffic…
|
CWE-20
Improper Input Validation
|
CVE-2019-5302
|
2024-11-21 13:44 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219045
|
4.3 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in …
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-4729
|
2024-11-21 13:44 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219046
|
5.3 |
MEDIUM
Network
|
ibm
|
cloud_app_management
|
IBM Cloud App Management 2019.3.0 and 2019.4.0 reveals a stack trace on certain API requests which can allow an attacker further information about the implementation of the offering. IBM X-Force ID: …
|
CWE-200
Information Exposure
|
CVE-2019-4751
|
2024-11-21 13:44 |
2020-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219047
|
8.8 |
HIGH
Network
|
ibm
|
cloud_app_management
|
IBM Cloud App Management 2019.3.0 and 2019.4.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the…
|
CWE-352
Origin Validation Error
|
CVE-2019-4750
|
2024-11-21 13:44 |
2020-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219048
|
4.6 |
MEDIUM
Physics
|
ibm
|
maas360
|
IBM MaaS360 3.96.62 for iOS could allow an attacker with physical access to the device to obtain sensitive information from the agent outside of the container. IBM X-Force ID: 172705.
|
NVD-CWE-noinfo
|
CVE-2019-4735
|
2024-11-21 13:44 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219049
|
5.4 |
MEDIUM
Network
|
ibm
|
maximo_for_life_sciences maximo_for_transportation control_desk maximo_asset_management maximo_for_oil_and_gas tivoli_integration_composer maximo_for_aviation maximo_for_utilitie…
|
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potent…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4749
|
2024-11-21 13:44 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219050
|
7.5 |
HIGH
Network
|
ibm
|
mq
|
IBM MQ 9.0 and 9.1 is vulnerable to a denial of service attack due to an error in the Channel processing function. IBM X-Force ID: 173625.
|
NVD-CWE-noinfo
|
CVE-2019-4762
|
2024-11-21 13:44 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|