Show filters
8,081 Total Results
Displaying 121-130 of 8,081
Sort by:
Attacker Value
Unknown
CVE-2023-47159
Disclosure Date: January 27, 2025 (last updated January 28, 2025)
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.
0
Attacker Value
Unknown
CVE-2024-28771
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
0
Attacker Value
Unknown
CVE-2024-28770
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
0
Attacker Value
Unknown
CVE-2024-28766
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.
0
Attacker Value
Unknown
CVE-2023-46187
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2023-50946
Disclosure Date: January 26, 2025 (last updated January 27, 2025)
IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism.
0
Attacker Value
Unknown
CVE-2023-50945
Disclosure Date: January 26, 2025 (last updated January 27, 2025)
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.
0
Attacker Value
Unknown
CVE-2023-38009
Disclosure Date: January 26, 2025 (last updated January 27, 2025)
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.
0
Attacker Value
Unknown
CVE-2024-31906
Disclosure Date: January 26, 2025 (last updated January 27, 2025)
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.
0
Attacker Value
Unknown
CVE-2024-35150
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.
0