Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Very High
CVE-2013-3018
Disclosure Date: May 24, 2018 (last updated November 26, 2024)
The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct request, as demonstrated by happyaxis.jsp. IBM X-Force ID: 84354.
0
Attacker Value
Unknown
CVE-2025-23227
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2023-47142
Disclosure Date: February 02, 2024 (last updated February 09, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267.
0
Attacker Value
Unknown
CVE-2023-47144
Disclosure Date: February 02, 2024 (last updated February 09, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 270271.
0
Attacker Value
Unknown
CVE-2023-47143
Disclosure Date: February 02, 2024 (last updated February 09, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 270270.
0
Attacker Value
Unknown
CVE-2018-1675
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are configured to use TADDM. IBM X-Force ID: 145110.
0
Attacker Value
Unknown
CVE-2018-1455
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 11029.
0
Attacker Value
Unknown
CVE-2013-3017
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
IBM Tivoli Application Dependency Discovery Manager (TADDM) before 7.2.1.5 and 7.2.x before 7.2.2 make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging support for weak SSL ciphers. IBM X-Force ID: 84353.
0
Attacker Value
Unknown
CVE-2013-3023
Disclosure Date: May 24, 2018 (last updated November 26, 2024)
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used. IBM X-Force ID: 84361.
0
Attacker Value
Unknown
CVE-2013-4040
Disclosure Date: May 01, 2018 (last updated November 26, 2024)
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2.x before 7.2.1.5 and 7.2.x before 7.2.2.0 on Unix use weak permissions (755) for unspecified configuration and log files, which allows local users to obtain sensitive information by reading the files. IBM X-Force ID: 86176.
0