Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown
CVE-2023-27540
Disclosure Date: July 10, 2023 (last updated February 25, 2025)
IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.
0
Attacker Value
Unknown
CVE-2023-30444
Disclosure Date: April 27, 2023 (last updated February 24, 2025)
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.
0
Attacker Value
Unknown
CVE-2022-36769
Disclosure Date: April 26, 2023 (last updated February 24, 2025)
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034.
0
Attacker Value
Unknown
CVE-2022-41731
Disclosure Date: February 12, 2023 (last updated February 24, 2025)
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 237402.
0
Attacker Value
Unknown
CVE-2022-41297
Disclosure Date: December 01, 2022 (last updated February 24, 2025)
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.
0
Attacker Value
Unknown
CVE-2021-38971
Disclosure Date: March 11, 2022 (last updated October 07, 2023)
IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an authorized user to bypass data masking rules and obtain sensitve information. IBM X-Force ID: 212620.
0
Attacker Value
Unknown
CVE-2021-38899
Disclosure Date: September 17, 2021 (last updated November 28, 2024)
IBM Cloud Pak for Data 2.5 could allow a local user with special privileges to obtain highly sensitive information. IBM X-Force ID: 209575.
0
Attacker Value
Unknown
CVE-2021-20486
Disclosure Date: May 25, 2021 (last updated November 28, 2024)
IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.
0
Attacker Value
Unknown
CVE-2019-4428
Disclosure Date: December 09, 2019 (last updated November 27, 2024)
IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162807.
0