Show filters
425 Total Results
Displaying 381-390 of 425
Sort by:
Attacker Value
Unknown
CVE-2021-20396
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
IBM QRadar Analyst Workflow App 1.0 through 1.18.0 for IBM QRadar SIEM allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 196009.
0
Attacker Value
Unknown
CVE-2020-5008
Disclosure Date: June 04, 2021 (last updated February 22, 2025)
IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 193033.
0
Attacker Value
Unknown
CVE-2021-32635
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint. An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container. Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint. The vulnerability is patched in Singularity version 3.7.4. Two possible workarounds exist: Users can only interact with the default remote endpoint, or an installation can have an execution control list configured to restrict execution to containers signed …
0
Attacker Value
Unknown
CVE-2021-20575
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.
0
Attacker Value
Unknown
CVE-2020-28911
Disclosure Date: May 24, 2021 (last updated February 22, 2025)
Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.
0
Attacker Value
Unknown
CVE-2020-4765
Disclosure Date: May 18, 2021 (last updated February 22, 2025)
IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 188902.
0
Attacker Value
Unknown
CVE-2021-20391
Disclosure Date: May 13, 2021 (last updated February 22, 2025)
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 195999.
0
Attacker Value
Unknown
CVE-2021-25379
Disclosure Date: April 09, 2021 (last updated February 22, 2025)
Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.
0
Attacker Value
Unknown
CVE-2021-21390
Disclosure Date: March 19, 2021 (last updated February 22, 2025)
MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-17T02-33-02Z, there is a vulnerability which enables MITM modification of request bodies that are meant to have integrity guaranteed by chunk signatures. In a PUT request using aws-chunked encoding, MinIO ordinarily verifies signatures at the end of a chunk. This check can be skipped if the client sends a false chunk size that is much greater than the actual data sent: the server accepts and completes the request without ever reaching the end of the chunk + thereby without ever checking the chunk signature. This is fixed in version RELEASE.2021-03-17T02-33-02Z. As a workaround one can avoid using "aws-chunked" encoding-based chunk signature upload requests instead use TLS. MinIO SDKs automatically disable chunked encoding signature when the server endpoint is configured with TLS.
0
Attacker Value
Unknown
CVE-2021-28653
Disclosure Date: March 19, 2021 (last updated February 22, 2025)
The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has Secure Enclave support but lacks biometric authentication hardware.
0