Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown
CVE-2020-4917
Disclosure Date: January 02, 2021 (last updated February 22, 2025)
IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191391.
0
Attacker Value
Unknown
CVE-2020-4913
Disclosure Date: January 02, 2021 (last updated February 22, 2025)
IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288.
0
Attacker Value
Unknown
CVE-2020-4910
Disclosure Date: January 02, 2021 (last updated February 22, 2025)
IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191274.
0
Attacker Value
Unknown
CVE-2020-4912
Disclosure Date: January 02, 2021 (last updated November 28, 2024)
IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user. IBM X-Force ID: 191287.
0
Attacker Value
Unknown
CVE-2020-4918
Disclosure Date: January 02, 2021 (last updated February 22, 2025)
IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct object reference in sell service console for the Platform System Manager. IBM X-Force ID: 191392.
0
Attacker Value
Unknown
CVE-2020-4919
Disclosure Date: January 02, 2021 (last updated November 28, 2024)
IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to impersonate another user on the system. IBM X-Force ID: 191395.
0
Attacker Value
Unknown
CVE-2020-4916
Disclosure Date: January 02, 2021 (last updated February 22, 2025)
IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191390.
0
Attacker Value
Unknown
CVE-2020-4928
Disclosure Date: January 02, 2021 (last updated February 22, 2025)
IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the attacker could execute arbitrary code on the server. IBM X-Force ID: 191705.
0
Attacker Value
Unknown
CVE-2020-4909
Disclosure Date: January 02, 2021 (last updated February 22, 2025)
IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191273.
0
Attacker Value
Unknown
CVE-2019-4095
Disclosure Date: December 10, 2019 (last updated November 27, 2024)
IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158015.
0