Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Ibm Subscribe
Total 6536 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-4552 1 Ibm 1 I2 Analysts Notebook 2021-07-21 6.9 MEDIUM 7.8 HIGH
IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183320.
CVE-2020-4553 1 Ibm 1 I2 Analysts Notebook 2021-07-21 6.9 MEDIUM 7.8 HIGH
IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183321.
CVE-2019-4704 1 Ibm 1 Security Identity Manager Virtual Appliance 2021-07-21 4.3 MEDIUM 4.3 MEDIUM
IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 172014.
CVE-2020-4357 1 Ibm 1 Spectrum Scale 2021-07-21 4.0 MEDIUM 4.3 MEDIUM
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 178761.
CVE-2020-4549 1 Ibm 1 I2 Analysts Notebook 2021-07-21 6.9 MEDIUM 7.8 HIGH
IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183317.
CVE-2020-4534 1 Ibm 1 Websphere Application Server 2021-07-21 7.2 HIGH 8.8 HIGH
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges. IBM X-Force ID: 182808.
CVE-2020-4873 1 Ibm 1 Planning Analytics 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.
CVE-2019-4541 1 Ibm 1 Security Directory Server 2021-07-21 6.5 MEDIUM 7.2 HIGH
IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 165814.
CVE-2020-4532 1 Ibm 2 Business Automation Workflow, Business Process Manager 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182716.
CVE-2020-4550 1 Ibm 1 I2 Analysts Notebook 2021-07-21 6.9 MEDIUM 7.8 HIGH
IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183318.
CVE-2020-4352 1 Ibm 1 Mq For Hpe Nonstop 2021-07-21 4.4 MEDIUM 7.0 HIGH
IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427.
CVE-2020-4841 2 Ibm, Microsoft 2 Security Secret Server, Windows 2021-07-21 4.3 MEDIUM 5.9 MEDIUM
IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 190045.
CVE-2019-4478 1 Ibm 1 Maximo Asset Management 2021-07-21 4.0 MEDIUM 6.5 MEDIUM
IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information that they should not normally have access to. IBM X-Force ID: 163998.
CVE-2019-4735 2 Apple, Ibm 2 Iphone Os, Maas360 2021-07-21 2.1 LOW 4.6 MEDIUM
IBM MaaS360 3.96.62 for iOS could allow an attacker with physical access to the device to obtain sensitive information from the agent outside of the container. IBM X-Force ID: 172705.
CVE-2020-4348 1 Ibm 1 Spectrum Scale 2021-07-21 4.0 MEDIUM 6.5 MEDIUM
IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform unauthorized actions due to missing function level access control. IBM X-Force ID: 178414
CVE-2020-4832 1 Ibm 2 Aix, Powerha 2021-07-21 2.1 LOW 5.5 MEDIUM
IBM PowerHA 7.2 could allow a local attacker to obtain sensitive information from temporary directories after a discovery failure occurs. IBM X-Force ID: 189969.
CVE-2020-4353 1 Ibm 1 Maas360 2021-07-21 2.1 LOW 4.6 MEDIUM
IBM MaaS360 6.82 could allow a user with pysical access to the device to crash the application which may enable the user to access restricted applications and device settings. IBM X-Force ID: 178505.
CVE-2020-4528 1 Ibm 1 Datapower Gateway 2021-07-21 1.9 LOW 5.5 MEDIUM
IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain highly sensitive information from log files. IBM X-Force ID: 182658.
CVE-2020-4347 1 Ibm 1 Infosphere Information Server 2021-07-21 7.5 HIGH 7.3 HIGH
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to inappropriate file permissions for files used by WebSphere Application Server Network Deployment. IBM X-Force ID: 178412.
CVE-2020-4816 1 Ibm 1 Cloud Pak For Security 2021-07-21 4.3 MEDIUM 5.9 MEDIUM
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 189703.