Show filters
3,316 Total Results
Displaying 261-270 of 3,316
Sort by:
Attacker Value
Unknown
CVE-2021-20451
Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 196643.
0
Attacker Value
Unknown
CVE-2023-40696
Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 264939.
0
Attacker Value
Unknown
CVE-2023-38724
Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 262183.
0
Attacker Value
Unknown
CVE-2023-28952
Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.
0
Attacker Value
Unknown
CVE-2023-23474
Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 245403.
0
Attacker Value
Unknown
CVE-2021-20556
Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.
0
Attacker Value
Unknown
CVE-2021-20450
Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 196640.
0
Attacker Value
Unknown
CVE-2020-4874
Disclosure Date: May 03, 2024 (last updated February 26, 2025)
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 190837.
0
Attacker Value
Unknown
CVE-2023-51605
Disclosure Date: May 03, 2024 (last updated February 26, 2025)
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of XML files. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of the current process.
. Was ZDI-CAN-18644.
0
Attacker Value
Unknown
CVE-2023-51604
Disclosure Date: May 03, 2024 (last updated February 26, 2025)
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of XML files. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of the current process.
. Was ZDI-CAN-18593.
0