Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown

CVE-2020-4726

Disclosure Date: February 26, 2021 (last updated February 22, 2025)
The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975.
Attacker Value
Unknown

CVE-2021-27170

Disclosure Date: February 10, 2021 (last updated February 22, 2025)
An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no firewall rules for IPv6 connectivity, exposing the internal management interfaces to the Internet.
Attacker Value
Unknown

CVE-2021-25776

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
Attacker Value
Unknown

CVE-2020-29603

Disclosure Date: January 29, 2021 (last updated February 22, 2025)
In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manage_proj_edit_page.php project_id parameter, without having access to them.
Attacker Value
Unknown

CVE-2020-4871

Disclosure Date: January 18, 2021 (last updated February 22, 2025)
IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.
Attacker Value
Unknown

CVE-2020-4674

Disclosure Date: January 11, 2021 (last updated February 22, 2025)
IBM Workload Automation 9.5 stores the server path in URLs that could aid in further attacks against the system. IBM X-Force ID: 186287.
Attacker Value
Unknown

CVE-2020-4673

Disclosure Date: January 11, 2021 (last updated February 22, 2025)
IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the system. IBM X-Force ID: 186286.
Attacker Value
Unknown

CVE-2020-9202

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific scenario, the attacker can gain information in the victim's device to launch the attack, successful exploit could cause information disclosure.
Attacker Value
Unknown

CVE-2020-26176

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them.
Attacker Value
Unknown

CVE-2020-4906

Disclosure Date: December 15, 2020 (last updated February 22, 2025)
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.