|
195181
|
8.2 |
HIGH
Network
|
ibm
|
i
|
IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could e…
|
NVD-CWE-noinfo
|
CVE-2021-20501
|
2024-11-21 14:46 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195182
|
8.2 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to e…
|
CWE-611
XXE
|
CVE-2021-20454
|
2024-11-21 14:46 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195183
|
8.2 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose…
|
CWE-611
XXE
|
CVE-2021-20453
|
2024-11-21 14:46 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195184
|
6.1 |
MEDIUM
Local
|
samba redhat fedoraproject
|
cifs-utils enterprise_linux fedora
|
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vul…
|
CWE-269
Improper Privilege Management
|
CVE-2021-20208
|
2024-11-21 14:46 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195185
|
7.2 |
HIGH
Network
|
ibm
|
resilient
|
IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198759.
|
CWE-77
Command Injection
|
CVE-2021-20527
|
2024-11-21 14:46 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195186
|
4.4 |
MEDIUM
Local
|
ibm
|
spectrum_protect
|
IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking during the parsing of commands. By issuing such a command with an improper param…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20491
|
2024-11-21 14:46 |
2021-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195187
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
got2000_gt27_firmware got2000_gt25_firmware gt2107-wtbd_firmware gt2107-wtsd_firmware gs2110-wtbd-n_firmware gs2107-wtbd-n_firmware
|
Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 series GT25 model VNC server versions 01.39.010 and prior, GOT2000 series GT21 mode…
|
CWE-287
Improper Authentication
|
CVE-2021-20590
|
2024-11-21 14:46 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195188
|
7.2 |
HIGH
Network
|
linuxfoundation redhat fedoraproject debian
|
ceph ceph_storage fedora debian_linux
|
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who …
|
CWE-287
Improper Authentication
|
CVE-2021-20288
|
2024-11-21 14:46 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195189
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_engineering_lifecycle_manager rhapsody_model_manager collaborative_lifecycle_management engineering_test_management engineeri…
|
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20519
|
2024-11-21 14:46 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195190
|
6.5 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vuln…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-20480
|
2024-11-21 14:46 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|