Show filters
1,998 Total Results
Displaying 171-180 of 1,998
Sort by:
Attacker Value
Unknown

CVE-2023-38724

Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 262183.
Attacker Value
Unknown

CVE-2023-28952

Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.
Attacker Value
Unknown

CVE-2023-23474

Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 245403.
Attacker Value
Unknown

CVE-2021-20556

Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.
Attacker Value
Unknown

CVE-2021-20450

Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 196640.
0
Attacker Value
Unknown

CVE-2020-4874

Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 190837.
Attacker Value
Unknown

CVE-2024-33518

Disclosure Date: May 01, 2024 (last updated February 26, 2025)
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
0
Attacker Value
Unknown

CVE-2024-33517

Disclosure Date: May 01, 2024 (last updated February 26, 2025)
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
0
Attacker Value
Unknown

CVE-2024-33516

Disclosure Date: May 01, 2024 (last updated February 26, 2025)
An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the controller.
0
Attacker Value
Unknown

CVE-2024-33515

Disclosure Date: May 01, 2024 (last updated February 26, 2025)
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected service.
0