Show filters
133 Total Results
Displaying 31-40 of 133
Sort by:
Attacker Value
Unknown
CVE-2022-36777
Disclosure Date: November 22, 2023 (last updated November 30, 2023)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.16.0could allow an authenticated user to obtain sensitive version information that could aid in further attacks against the system. IBM X-Force ID: 233665.
0
Attacker Value
Unknown
CVE-2023-39246
Disclosure Date: November 16, 2023 (last updated November 30, 2023)
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local malicious user could potentially exploit this vulnerability to create an arbitrary folder inside a restricted directory, leading to Privilege Escalation
0
Attacker Value
Unknown
CVE-2022-33161
Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.
0
Attacker Value
Unknown
CVE-2022-32755
Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.
0
Attacker Value
Unknown
CVE-2022-33160
Disclosure Date: October 06, 2023 (last updated October 11, 2023)
IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228568.
0
Attacker Value
Unknown
CVE-2022-33166
Disclosure Date: June 15, 2023 (last updated October 08, 2023)
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 228586.
0
Attacker Value
Unknown
CVE-2022-32757
Disclosure Date: June 15, 2023 (last updated October 08, 2023)
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 228510.
0
Attacker Value
Unknown
CVE-2022-32752
Disclosure Date: June 15, 2023 (last updated October 08, 2023)
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 228439.
0
Attacker Value
Unknown
CVE-2022-33168
Disclosure Date: June 15, 2023 (last updated October 08, 2023)
IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 228588.
0
Attacker Value
Unknown
CVE-2022-33163
Disclosure Date: June 15, 2023 (last updated October 08, 2023)
IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 228571.
0