Show filters
432 Total Results
Displaying 21-30 of 432
Sort by:
Attacker Value
Unknown

CVE-2023-50964

Disclosure Date: June 30, 2024 (last updated August 01, 2024)
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 276102.
Attacker Value
Unknown

CVE-2024-31898

Disclosure Date: June 30, 2024 (last updated August 01, 2024)
IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM X-Force ID: 288182.
Attacker Value
Unknown

CVE-2024-28797

Disclosure Date: June 30, 2024 (last updated August 01, 2024)
IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 287136.
Attacker Value
Unknown

CVE-2023-50953

Disclosure Date: June 30, 2024 (last updated August 01, 2024)
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. IBM X-Force ID: 275775.
Attacker Value
Unknown

CVE-2023-50952

Disclosure Date: June 30, 2024 (last updated August 01, 2024)
IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 275774.
Attacker Value
Unknown

CVE-2024-35119

Disclosure Date: June 30, 2024 (last updated August 01, 2024)
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 290342.
Attacker Value
Unknown

CVE-2024-31902

Disclosure Date: June 30, 2024 (last updated August 01, 2024)
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 289234.
Attacker Value
Unknown

CVE-2024-28798

Disclosure Date: June 30, 2024 (last updated August 01, 2024)
IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 287172.
Attacker Value
Unknown

CVE-2023-50954

Disclosure Date: June 30, 2024 (last updated August 22, 2024)
IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.
Attacker Value
Unknown

CVE-2024-28795

Disclosure Date: June 30, 2024 (last updated August 21, 2024)
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286832.