|
222211
|
7.1 |
HIGH
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed…
|
CWE-91
Blind XPath Injection
|
CVE-2019-4539
|
2024-11-21 13:43 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222212
|
7.5 |
HIGH
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-4520
|
2024-11-21 13:43 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222213
|
8.2 |
HIGH
Network
|
ibm
|
security_directory_server
|
IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote at…
|
CWE-601
Open Redirect
|
CVE-2019-4538
|
2024-11-21 13:43 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222214
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4497
|
2024-11-21 13:43 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222215
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4495
|
2024-11-21 13:43 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222216
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4494
|
2024-11-21 13:43 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222217
|
5.3 |
MEDIUM
Network
|
ibm
|
daeja_viewone
|
IBM Daeja ViewONE Virtual 5.0 through 5.0.6 could expose internal parameters to ViewONE clients that could be used in further attacks against the system. IBM X-Force ID: 159521.
|
NVD-CWE-noinfo
|
CVE-2019-4246
|
2024-11-21 13:43 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222218
|
5.3 |
MEDIUM
Network
|
ibm
|
sterling_file_gateway
|
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequ…
|
CWE-22
Path Traversal
|
CVE-2019-4423
|
2024-11-21 13:43 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222219
|
5.3 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the improper setting of a cookie. IBM X-Force ID: 160951.
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2019-4305
|
2024-11-21 13:43 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222220
|
6.3 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950.
|
CWE-384
Session Fixation
|
CVE-2019-4304
|
2024-11-21 13:43 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|