Show filters
556 Total Results
Displaying 101-110 of 556
Sort by:
Attacker Value
Unknown
CVE-2023-28958
Disclosure Date: July 10, 2023 (last updated October 08, 2023)
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.
0
Attacker Value
Unknown
CVE-2023-28955
Disclosure Date: July 10, 2023 (last updated October 08, 2023)
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.
0
Attacker Value
Unknown
CVE-2023-36301
Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.
0
Attacker Value
Unknown
CVE-2023-33247
Disclosure Date: May 26, 2023 (last updated October 08, 2023)
Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.)
0
Attacker Value
Unknown
CVE-2023-22355
Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-30444
Disclosure Date: April 27, 2023 (last updated October 08, 2023)
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.
0
Attacker Value
Unknown
CVE-2023-26264
Disclosure Date: April 13, 2023 (last updated October 08, 2023)
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.
0
Attacker Value
Unknown
CVE-2023-26263
Disclosure Date: April 13, 2023 (last updated October 08, 2023)
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting server.
0
Attacker Value
Unknown
CVE-2023-28069
Disclosure Date: April 05, 2023 (last updated October 08, 2023)
Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing attacks.
0
Attacker Value
Unknown
CVE-2023-27538
Disclosure Date: March 30, 2023 (last updated March 28, 2024)
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.
0