Show filters
7,652 Total Results
Displaying 151-160 of 7,652
Sort by:
Attacker Value
Unknown
CVE-2024-45091
Disclosure Date: January 21, 2025 (last updated January 30, 2025)
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
0
Attacker Value
Unknown
CVE-2024-22349
Disclosure Date: January 20, 2025 (last updated January 21, 2025)
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.
0
Attacker Value
Unknown
CVE-2024-22348
Disclosure Date: January 20, 2025 (last updated January 21, 2025)
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
0
Attacker Value
Unknown
CVE-2024-22347
Disclosure Date: January 20, 2025 (last updated January 21, 2025)
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
0
Attacker Value
Unknown
CVE-2024-45647
Disclosure Date: January 20, 2025 (last updated January 30, 2025)
IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.
0
Attacker Value
Unknown
CVE-2024-41783
Disclosure Date: January 19, 2025 (last updated January 20, 2025)
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input.
0
Attacker Value
Unknown
CVE-2024-41743
Disclosure Date: January 19, 2025 (last updated January 20, 2025)
IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources.
0
Attacker Value
Unknown
CVE-2024-41742
Disclosure Date: January 19, 2025 (last updated January 20, 2025)
IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.
0
Attacker Value
Unknown
CVE-2024-38337
Disclosure Date: January 19, 2025 (last updated January 20, 2025)
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.
0
Attacker Value
Unknown
CVE-2024-45654
Disclosure Date: January 19, 2025 (last updated January 19, 2025)
IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs.
0