Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2023-27540

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.
Attacker Value
Unknown

CVE-2023-30444

Disclosure Date: April 27, 2023 (last updated February 24, 2025)
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.
Attacker Value
Unknown

CVE-2022-36769

Disclosure Date: April 26, 2023 (last updated February 24, 2025)
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034.
Attacker Value
Unknown

CVE-2022-41731

Disclosure Date: February 12, 2023 (last updated February 24, 2025)
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 237402.
Attacker Value
Unknown

CVE-2022-41297

Disclosure Date: December 01, 2022 (last updated February 24, 2025)
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.
Attacker Value
Unknown

CVE-2021-38971

Disclosure Date: March 11, 2022 (last updated October 07, 2023)
IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an authorized user to bypass data masking rules and obtain sensitve information. IBM X-Force ID: 212620.
Attacker Value
Unknown

CVE-2021-38899

Disclosure Date: September 17, 2021 (last updated November 28, 2024)
IBM Cloud Pak for Data 2.5 could allow a local user with special privileges to obtain highly sensitive information. IBM X-Force ID: 209575.
Attacker Value
Unknown

CVE-2021-20486

Disclosure Date: May 25, 2021 (last updated November 28, 2024)
IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.
Attacker Value
Unknown

CVE-2019-4428

Disclosure Date: December 09, 2019 (last updated November 27, 2024)
IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162807.