Show filters
8,101 Total Results
Displaying 261-270 of 8,101
Sort by:
Attacker Value
Unknown
CVE-2024-25042
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3
is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations.
0
Attacker Value
Unknown
CVE-2024-52361
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
stores user credentials in plain text which can be read by an authenticated user with access to the pod.
0
Attacker Value
Unknown
CVE-2024-47119
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client.
0
Attacker Value
Unknown
CVE-2023-50956
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.
0
Attacker Value
Unknown
CVE-2024-47104
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges.
0
Attacker Value
Unknown
CVE-2024-49820
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
0
Attacker Value
Unknown
CVE-2024-49819
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
0
Attacker Value
Unknown
CVE-2024-49818
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1
could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-49817
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
0
Attacker Value
Unknown
CVE-2024-49816
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
0