Show filters
7,652 Total Results
Displaying 181-190 of 7,652
Sort by:
Attacker Value
Unknown

CVE-2024-40679

Disclosure Date: January 08, 2025 (last updated February 01, 2025)
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.
Attacker Value
Unknown

CVE-2024-40702

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.
Attacker Value
Unknown

CVE-2024-28778

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization.
Attacker Value
Unknown

CVE-2024-25037

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.
Attacker Value
Unknown

CVE-2022-22363

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2021-20455

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2024-45640

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2024-45100

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources.
Attacker Value
Unknown

CVE-2024-52893

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3  could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2024-52891

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization.