Show filters
400 Total Results
Displaying 161-170 of 400
Sort by:
Attacker Value
Unknown
CVE-2021-20399
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196073.
0
Attacker Value
Unknown
CVE-2021-20337
Disclosure Date: July 23, 2021 (last updated February 23, 2025)
IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448.
0
Attacker Value
Unknown
CVE-2020-4980
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
0
Attacker Value
Unknown
CVE-2020-24133
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.
0
Attacker Value
Unknown
CVE-2021-20396
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
IBM QRadar Analyst Workflow App 1.0 through 1.18.0 for IBM QRadar SIEM allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 196009.
0
Attacker Value
Unknown
CVE-2021-20380
Disclosure Date: June 02, 2021 (last updated November 28, 2024)
IBM QRadar Advisor With Watson App 1.1 through 2.5 as used on IBM QRadar SIEM 7.4 could allow a remote user to obtain sensitive information from HTTP requests that could aid in further attacks against the system. IBM X-Force ID: 195712.
0
Attacker Value
Unknown
CVE-2021-32613
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
0
Attacker Value
Unknown
CVE-2021-20429
Disclosure Date: May 13, 2021 (last updated February 22, 2025)
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force ID: 196334.
0
Attacker Value
Unknown
CVE-2021-20392
Disclosure Date: May 13, 2021 (last updated February 22, 2025)
IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2021-20391
Disclosure Date: May 13, 2021 (last updated February 22, 2025)
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 195999.
0