Show filters
7,652 Total Results
Displaying 121-130 of 7,652
Sort by:
Attacker Value
Unknown
CVE-2024-31906
Disclosure Date: January 26, 2025 (last updated January 27, 2025)
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.
0
Attacker Value
Unknown
CVE-2024-35150
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.
0
Attacker Value
Unknown
CVE-2024-35148
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
0
Attacker Value
Unknown
CVE-2024-35145
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2024-35144
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-39750
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Analytics Content Hub 2.0 is vulnerable to a buffer overflow due to improper return length checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.
0
Attacker Value
Unknown
CVE-2024-35134
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-35114
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Control Center 6.2.1 and 6.3.1
could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.
0
Attacker Value
Unknown
CVE-2024-35113
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Control Center 6.2.1 and 6.3.1
could allow an authenticated user to obtain sensitive information exposed through a directory listing.
0
Attacker Value
Unknown
CVE-2024-35112
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Control Center 6.2.1 and 6.3.1
could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
0