Show filters
4,200 Total Results
Displaying 251-260 of 4,200
Sort by:
Attacker Value
Unknown

CVE-2024-6676

Disclosure Date: July 11, 2024 (last updated July 11, 2024)
A vulnerability has been found in witmy my-springsecurity-plus up to 2024-07-03 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/user. The manipulation of the argument params.dataScope leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-271111.
0
Attacker Value
Unknown

CVE-2023-35006

Disclosure Date: July 10, 2024 (last updated August 03, 2024)
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 297165.
Attacker Value
Unknown

CVE-2023-33860

Disclosure Date: July 10, 2024 (last updated August 03, 2024)
IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 257702.
Attacker Value
Unknown

CVE-2023-33859

Disclosure Date: July 10, 2024 (last updated August 01, 2024)
IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.
Attacker Value
Unknown

CVE-2024-25023

Disclosure Date: July 10, 2024 (last updated September 21, 2024)
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429.
Attacker Value
Unknown

CVE-2022-38383

Disclosure Date: June 28, 2024 (last updated August 02, 2024)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.
Attacker Value
Unknown

CVE-2024-35139

Disclosure Date: June 28, 2024 (last updated August 02, 2024)
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.
Attacker Value
Unknown

CVE-2024-35137

Disclosure Date: June 28, 2024 (last updated August 01, 2024)
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.
Attacker Value
Unknown

CVE-2023-38370

Disclosure Date: June 27, 2024 (last updated August 01, 2024)
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.
Attacker Value
Unknown

CVE-2023-38368

Disclosure Date: June 27, 2024 (last updated August 03, 2024)
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls. IBM X-Force ID: 261195.