Show filters
48 Total Results
Displaying 21-30 of 48
Sort by:
Attacker Value
Unknown
CVE-2021-39089
Disclosure Date: January 20, 2023 (last updated November 08, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 216387.
0
Attacker Value
Unknown
CVE-2021-39011
Disclosure Date: January 20, 2023 (last updated November 08, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645.
0
Attacker Value
Unknown
CVE-2022-38385
Disclosure Date: November 15, 2022 (last updated November 08, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 233777.
0
Attacker Value
Unknown
CVE-2022-36776
Disclosure Date: November 11, 2022 (last updated November 08, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233663.
0
Attacker Value
Unknown
CVE-2022-38387
Disclosure Date: November 11, 2022 (last updated November 08, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 233786.
0
Attacker Value
Unknown
CVE-2021-39013
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses that could be used in further attacks against the system. IBM X-Force ID: 213651.
0
Attacker Value
Unknown
CVE-2021-20578
Disclosure Date: September 29, 2021 (last updated February 23, 2025)
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.
0
Attacker Value
Unknown
CVE-2021-29894
Disclosure Date: September 29, 2021 (last updated February 23, 2025)
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207320.
0
Attacker Value
Unknown
CVE-2021-29697
Disclosure Date: July 30, 2021 (last updated November 28, 2024)
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to obtain sensitive information through HTTP requests that could be used in further attacks against the system.
0
Attacker Value
Unknown
CVE-2021-20541
Disclosure Date: July 30, 2021 (last updated November 28, 2024)
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information could be used in further attacks against the system. IBM X-Force ID: 198927.
0