Show filters
7,652 Total Results
Displaying 171-180 of 7,652
Sort by:
Attacker Value
Unknown
CVE-2024-51462
Disclosure Date: January 17, 2025 (last updated January 17, 2025)
IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.
0
Attacker Value
Unknown
CVE-2024-52363
Disclosure Date: January 17, 2025 (last updated January 17, 2025)
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
0
Attacker Value
Unknown
CVE-2024-41746
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2024-52898
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.
0
Attacker Value
Unknown
CVE-2024-51456
Disclosure Date: January 12, 2025 (last updated January 13, 2025)
IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.
0
Attacker Value
Unknown
CVE-2024-49785
Disclosure Date: January 12, 2025 (last updated January 12, 2025)
IBM watsonx.ai 1.1 through 2.0.3 and IBM watsonx.ai on Cloud Pak for Data 4.8 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2021-29669
Disclosure Date: January 12, 2025 (last updated January 12, 2025)
IBM Jazz Foundation 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2024-41787
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.
0
Attacker Value
Unknown
CVE-2024-43176
Disclosure Date: January 09, 2025 (last updated January 10, 2025)
IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users.
0
Attacker Value
Unknown
CVE-2022-22491
Disclosure Date: January 09, 2025 (last updated January 10, 2025)
IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, and 12.4 operands running in Red Hat OpenShift do not restrict writing to the local filesystem, which may result in exhausting the available storage in a Pod, resulting in that Pod being restarted.
0