Show filters
48 Total Results
Displaying 41-48 of 48
Sort by:
Attacker Value
Unknown
CVE-2020-4967
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
IBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers which could be used in further attacks against the system. IBM X-Force ID: 192425.
0
Attacker Value
Unknown
CVE-2020-4628
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 185369.
0
Attacker Value
Unknown
CVE-2020-4816
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 189703.
0
Attacker Value
Unknown
CVE-2020-4625
Disclosure Date: November 25, 2020 (last updated February 22, 2025)
IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie.
0
Attacker Value
Unknown
CVE-2020-4627
Disclosure Date: November 25, 2020 (last updated February 22, 2025)
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
0
Attacker Value
Unknown
CVE-2020-4696
Disclosure Date: November 25, 2020 (last updated February 22, 2025)
IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session. IBM X-Force ID: 186789.
0
Attacker Value
Unknown
CVE-2020-4624
Disclosure Date: November 25, 2020 (last updated February 22, 2025)
IBM Cloud Pak for Security 1.3.0.1 (CP4S) uses weaker than expected cryptographic algorithms during negotiation could allow an attacker to decrypt sensitive information.
0
Attacker Value
Unknown
CVE-2020-4626
Disclosure Date: November 25, 2020 (last updated November 28, 2024)
IBM Cloud Pak for Security 1.3.0.1 (CP4S) could reveal sensitive information about the internal network to an authenticated user using a specially crafted HTTP request. IBM X-Force ID: 185362.
0