|
196511
|
6.2 |
MEDIUM
Local
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-20536
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196512
|
7.8 |
HIGH
Local
|
ibm
|
spectrum_protect_backup-archive_client spectrum_protect_for_virtual_environments
|
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 19…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-20532
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196513
|
6.5 |
MEDIUM
Network
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domai…
|
NVD-CWE-Other
|
CVE-2021-20432
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196514
|
6.1 |
MEDIUM
Network
|
nec
|
aterm_wg1900hp2_firmware aterm_wg1900hp_firmware aterm_wg1800hp4_firmware aterm_wg1800hp3_firmware aterm_wg1200hs3_firmware aterm_wg1200hs2_firmware aterm_wg1200hp3_firmware ater…
|
Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP firmware Ver.2.5.1 and earlier, Aterm WG1800HP4 firmware Ver.1.3.1 and earlier,…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20680
|
2024-11-21 14:46 |
2021-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196515
|
8.2 |
HIGH
Network
|
ibm
|
i
|
IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could e…
|
NVD-CWE-noinfo
|
CVE-2021-20501
|
2024-11-21 14:46 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196516
|
8.2 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to e…
|
CWE-611
XXE
|
CVE-2021-20454
|
2024-11-21 14:46 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196517
|
8.2 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose…
|
CWE-611
XXE
|
CVE-2021-20453
|
2024-11-21 14:46 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196518
|
6.1 |
MEDIUM
Local
|
samba redhat fedoraproject
|
cifs-utils enterprise_linux fedora
|
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vul…
|
CWE-269
Improper Privilege Management
|
CVE-2021-20208
|
2024-11-21 14:46 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196519
|
7.2 |
HIGH
Network
|
ibm
|
resilient
|
IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198759.
|
CWE-77
Command Injection
|
CVE-2021-20527
|
2024-11-21 14:46 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196520
|
4.4 |
MEDIUM
Local
|
ibm
|
spectrum_protect
|
IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking during the parsing of commands. By issuing such a command with an improper param…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20491
|
2024-11-21 14:46 |
2021-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|