Show filters
8,101 Total Results
Displaying 261-270 of 8,101
Sort by:
Attacker Value
Unknown

CVE-2024-25042

Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Explorations.
Attacker Value
Unknown

CVE-2024-52361

Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9  stores user credentials in plain text which can be read by an authenticated user with access to the pod.
Attacker Value
Unknown

CVE-2024-47119

Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client.
Attacker Value
Unknown

CVE-2023-50956

Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.
Attacker Value
Unknown

CVE-2024-47104

Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges.
Attacker Value
Unknown

CVE-2024-49820

Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Attacker Value
Unknown

CVE-2024-49819

Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
Attacker Value
Unknown

CVE-2024-49818

Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2024-49817

Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
Attacker Value
Unknown

CVE-2024-49816

Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.