Show filters
184 Total Results
Displaying 91-100 of 184
Sort by:
Attacker Value
Unknown

CVE-2021-20371

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.
Attacker Value
Unknown

CVE-2021-22885

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
Attacker Value
Unknown

CVE-2021-20428

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196315.
Attacker Value
Unknown

CVE-2021-29682

Disclosure Date: May 19, 2021 (last updated February 22, 2025)
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199997
Attacker Value
Unknown

CVE-2021-29688

Disclosure Date: May 19, 2021 (last updated February 22, 2025)
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102.
Attacker Value
Unknown

CVE-2021-29040

Disclosure Date: May 16, 2021 (last updated February 22, 2025)
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused attacks via crafted inputs.
Attacker Value
Unknown

CVE-2020-23995

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
Attacker Value
Unknown

CVE-2021-20393

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196001.
Attacker Value
Unknown

CVE-2020-19275

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.
Attacker Value
Unknown

CVE-2021-31341

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1).