Show filters
83 Total Results
Displaying 11-20 of 83
Sort by:
Attacker Value
Unknown
CVE-2021-38859
Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that could be used in further attacks against the system. IBM X-Force ID: 207899.
0
Attacker Value
Unknown
CVE-2021-29913
Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 207898.
0
Attacker Value
Unknown
CVE-2021-20581
Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324.
0
Attacker Value
Unknown
CVE-2022-22384
Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID: 221961.
0
Attacker Value
Unknown
CVE-2022-22377
Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 221827.
0
Attacker Value
Unknown
CVE-2023-5556
Disclosure Date: October 12, 2023 (last updated October 17, 2023)
Cross-site Scripting (XSS) - Reflected in GitHub repository structurizr/onpremises prior to 3194.
0
Attacker Value
Unknown
CVE-2023-32226
Disclosure Date: July 30, 2023 (last updated October 08, 2023)
Sysaid - CWE-552: Files or Directories Accessible to External Parties -
Authenticated users may exfiltrate files from the server via an unspecified method.
0
Attacker Value
Unknown
CVE-2023-32225
Disclosure Date: July 30, 2023 (last updated October 08, 2023)
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -
A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.
0
Attacker Value
Unknown
CVE-2022-28761
Disclosure Date: October 11, 2022 (last updated October 08, 2023)
Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.
0
Attacker Value
Unknown
CVE-2022-28759
Disclosure Date: September 13, 2022 (last updated October 08, 2023)
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.
0