Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown
CVE-2023-26024
Disclosure Date: December 01, 2023 (last updated February 25, 2025)
IBM Planning Analytics on Cloud Pak for Data 4.0 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication. IBM X-Force ID: 247898.
0
Attacker Value
Unknown
CVE-2023-38735
Disclosure Date: October 22, 2023 (last updated February 25, 2025)
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482.
0
Attacker Value
Unknown
CVE-2023-38276
Disclosure Date: October 22, 2023 (last updated February 25, 2025)
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736.
0
Attacker Value
Unknown
CVE-2023-38275
Disclosure Date: October 22, 2023 (last updated February 25, 2025)
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730.
0
Attacker Value
Unknown
CVE-2023-27877
Disclosure Date: July 19, 2023 (last updated February 25, 2025)
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
0
Attacker Value
Unknown
CVE-2023-26026
Disclosure Date: July 19, 2023 (last updated February 25, 2025)
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
0
Attacker Value
Unknown
CVE-2023-26023
Disclosure Date: July 19, 2023 (last updated February 25, 2025)
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
0
Attacker Value
Unknown
CVE-2023-28958
Disclosure Date: July 10, 2023 (last updated February 25, 2025)
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.
0
Attacker Value
Unknown
CVE-2023-28955
Disclosure Date: July 10, 2023 (last updated February 25, 2025)
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.
0
Attacker Value
Unknown
CVE-2023-28953
Disclosure Date: July 10, 2023 (last updated October 08, 2023)
IBM Cognos Analytics on Cloud Pak for Data 4.0 could allow an attacker to make system calls that might compromise the security of the containers due to misconfigured security context. IBM X-Force ID: 251465.
0