|
195071
|
7.5 |
HIGH
Network
|
ibm
|
cloud_pak_for_applications
|
IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195031.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2021-20360
|
2024-11-21 14:46 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195072
|
7.1 |
HIGH
Network
|
mitsubishi
|
g-50a_firmware gb-50a_firmware ag-150a-a_firmware ag-150a-j_firmware gb-50ada-a_firmware gb-50ada-j_firmware eb-50gu-a_firmware eb-50gu-j_firmware ae-200a_firmware ae-200e_…
|
Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.2.50 to Ver. 3.35, GB-50A Ver.2.50 to Ver. 3.35, AG-150A-A Ver.3…
|
CWE-287
Improper Authentication
|
CVE-2021-20593
|
2024-11-21 14:46 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195073
|
8.2 |
HIGH
Network
|
mitsubishi
|
g-50a_firmware gb-50a_firmware ag-150a-a_firmware ag-150a-j_firmware gb-50ada-a_firmware gb-50ada-j_firmware eb-50gu-a_firmware eb-50gu-j_firmware ae-200a_firmware ae-200e_…
|
Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.3.35 and prior, GB-50A Ver.3.35 and prior, GB-24A…
|
CWE-611
XXE
|
CVE-2021-20595
|
2024-11-21 14:46 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195074
|
4.9 |
MEDIUM
Network
|
ibm
|
guardium_data_encryption
|
IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly limiting the number of interactions. IBM X-Force ID: 196216.
|
NVD-CWE-Other
|
CVE-2021-20414
|
2024-11-21 14:46 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195075
|
7.5 |
HIGH
Network
|
ibm
|
guardium_data_encryption
|
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-20474
|
2024-11-21 14:46 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195076
|
4.3 |
MEDIUM
Network
|
ibm
|
guardium_data_encryption
|
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be …
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-20417
|
2024-11-21 14:46 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195077
|
5.3 |
MEDIUM
Network
|
ibm
|
guardium_data_encryption
|
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit t…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-20416
|
2024-11-21 14:46 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195078
|
7.5 |
HIGH
Network
|
ibm
|
guardium_data_encryption
|
IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-20415
|
2024-11-21 14:46 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195079
|
7.5 |
HIGH
Network
|
ibm
|
guardium_data_encryption
|
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195711.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-20379
|
2024-11-21 14:46 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195080
|
8.8 |
HIGH
Network
|
ibm
|
guardium_data_encryption
|
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 1957…
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-20378
|
2024-11-21 14:46 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|