Show filters
4,200 Total Results
Displaying 251-260 of 4,200
Sort by:
Attacker Value
Unknown
CVE-2024-6676
Disclosure Date: July 11, 2024 (last updated July 11, 2024)
A vulnerability has been found in witmy my-springsecurity-plus up to 2024-07-03 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/user. The manipulation of the argument params.dataScope leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-271111.
0
Attacker Value
Unknown
CVE-2023-35006
Disclosure Date: July 10, 2024 (last updated August 03, 2024)
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 297165.
0
Attacker Value
Unknown
CVE-2023-33860
Disclosure Date: July 10, 2024 (last updated August 03, 2024)
IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 257702.
0
Attacker Value
Unknown
CVE-2023-33859
Disclosure Date: July 10, 2024 (last updated August 01, 2024)
IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.
0
Attacker Value
Unknown
CVE-2024-25023
Disclosure Date: July 10, 2024 (last updated September 21, 2024)
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429.
0
Attacker Value
Unknown
CVE-2022-38383
Disclosure Date: June 28, 2024 (last updated August 02, 2024)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.
0
Attacker Value
Unknown
CVE-2024-35139
Disclosure Date: June 28, 2024 (last updated August 02, 2024)
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.
0
Attacker Value
Unknown
CVE-2024-35137
Disclosure Date: June 28, 2024 (last updated August 01, 2024)
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.
0
Attacker Value
Unknown
CVE-2023-38370
Disclosure Date: June 27, 2024 (last updated August 01, 2024)
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.
0
Attacker Value
Unknown
CVE-2023-38368
Disclosure Date: June 27, 2024 (last updated August 03, 2024)
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls. IBM X-Force ID: 261195.
0