Show filters
74 Total Results
Displaying 51-60 of 74
Sort by:
Attacker Value
Unknown
CVE-2022-22360
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 220782.
0
Attacker Value
Unknown
CVE-2022-22358
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 220651.
0
Attacker Value
Unknown
CVE-2022-22416
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 223126.
0
Attacker Value
Unknown
CVE-2021-39298
Disclosure Date: May 10, 2022 (last updated November 08, 2023)
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.
0
Attacker Value
Unknown
CVE-2022-22328
Disclosure Date: March 31, 2022 (last updated October 07, 2023)
IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform unintended operations to another users data. IBM X-Force ID: 218871.
0
Attacker Value
Unknown
CVE-2022-22332
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131.
0
Attacker Value
Unknown
CVE-2022-22331
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.
0
Attacker Value
Unknown
CVE-2021-39301
Disclosure Date: February 16, 2022 (last updated October 07, 2023)
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
0
Attacker Value
Unknown
CVE-2021-39300
Disclosure Date: February 16, 2022 (last updated October 07, 2023)
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
0
Attacker Value
Unknown
CVE-2021-39299
Disclosure Date: February 16, 2022 (last updated October 07, 2023)
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
0