Show filters
89 Total Results
Displaying 21-30 of 89
Sort by:
Attacker Value
Unknown

CVE-2020-4826

Disclosure Date: February 02, 2021 (last updated February 22, 2025)
IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189840.
Attacker Value
Unknown

CVE-2020-4828

Disclosure Date: February 02, 2021 (last updated February 22, 2025)
IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 189842.
Attacker Value
Unknown

CVE-2020-4838

Disclosure Date: January 11, 2021 (last updated February 22, 2025)
IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190036.
Attacker Value
Unknown

CVE-2020-4899

Disclosure Date: January 04, 2021 (last updated February 22, 2025)
IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of sensitive information across the network. IBM X-Force ID: 190990.
Attacker Value
Unknown

CVE-2020-4638

Disclosure Date: September 02, 2020 (last updated November 28, 2024)
IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can escalate privileges by manipulating the invitation link. IBM X-Force ID: 185508.
Attacker Value
Unknown

CVE-2020-4337

Disclosure Date: September 02, 2020 (last updated November 28, 2024)
IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs. IBM X-Force ID: 177933.
Attacker Value
Unknown

CVE-2020-10608

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.
Attacker Value
Unknown

CVE-2020-10610

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.
Attacker Value
Unknown

CVE-2020-10606

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a shared workstation or terminal server deployment.
Attacker Value
Unknown

CVE-2020-4452

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 181324.