Show filters
7,652 Total Results
Displaying 161-170 of 7,652
Sort by:
Attacker Value
Unknown
CVE-2024-45654
Disclosure Date: January 19, 2025 (last updated January 19, 2025)
IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs.
0
Attacker Value
Unknown
CVE-2024-45653
Disclosure Date: January 19, 2025 (last updated January 19, 2025)
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP address information to authenticated users in responses that could be used in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-45652
Disclosure Date: January 19, 2025 (last updated January 19, 2025)
IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
0
Attacker Value
Unknown
CVE-2024-45662
Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denial of service due to improper allocation of resources.
0
Attacker Value
Unknown
CVE-2024-49824
Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18
could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.
0
Attacker Value
Unknown
CVE-2024-49354
Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.
0
Attacker Value
Unknown
CVE-2024-47113
Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted XML statements, which would allow them to attacker to view or modify information in the XML document.
0
Attacker Value
Unknown
CVE-2024-47106
Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information from improper access restrictions that could aid in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-51448
Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A subsequent service or server restart will then run that binary with administrator privilege.
0
Attacker Value
Unknown
CVE-2024-49338
Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials.
0