Show filters
48 Total Results
Displaying 21-30 of 48
Sort by:
Attacker Value
Unknown

CVE-2021-39089

Disclosure Date: January 20, 2023 (last updated November 08, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 216387.
Attacker Value
Unknown

CVE-2021-39011

Disclosure Date: January 20, 2023 (last updated November 08, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645.
Attacker Value
Unknown

CVE-2022-38385

Disclosure Date: November 15, 2022 (last updated November 08, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 233777.
Attacker Value
Unknown

CVE-2022-36776

Disclosure Date: November 11, 2022 (last updated November 08, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233663.
Attacker Value
Unknown

CVE-2022-38387

Disclosure Date: November 11, 2022 (last updated November 08, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 233786.
Attacker Value
Unknown

CVE-2021-39013

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses that could be used in further attacks against the system. IBM X-Force ID: 213651.
Attacker Value
Unknown

CVE-2021-20578

Disclosure Date: September 29, 2021 (last updated February 23, 2025)
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.
Attacker Value
Unknown

CVE-2021-29894

Disclosure Date: September 29, 2021 (last updated February 23, 2025)
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207320.
Attacker Value
Unknown

CVE-2021-29697

Disclosure Date: July 30, 2021 (last updated November 28, 2024)
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to obtain sensitive information through HTTP requests that could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2021-20541

Disclosure Date: July 30, 2021 (last updated November 28, 2024)
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information could be used in further attacks against the system. IBM X-Force ID: 198927.