Show filters
375 Total Results
Displaying 71-80 of 375
Sort by:
Attacker Value
Unknown

CVE-2022-43928

Disclosure Date: April 07, 2023 (last updated November 08, 2023)
The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing. Since Java strings are immutable, their contents exist in memory until garbage collected. This means sensitive data could be visible in memory over an indefinite amount of time. IBM has addressed this issue by reducing the amount of time the sensitive data is visible in memory. IBM X-Force ID: 241675.
Attacker Value
Unknown

CVE-2022-43930

Disclosure Date: February 17, 2023 (last updated November 08, 2023)
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log file. IBM X-Force ID: 241677.
Attacker Value
Unknown

CVE-2022-43929

Disclosure Date: February 17, 2023 (last updated November 08, 2023)
IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-Force ID: 241676.
Attacker Value
Unknown

CVE-2022-43927

Disclosure Date: February 17, 2023 (last updated November 08, 2023)
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671.
Attacker Value
Unknown

CVE-2022-41296

Disclosure Date: December 12, 2022 (last updated November 08, 2023)
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210.
Attacker Value
Unknown

CVE-2022-41297

Disclosure Date: December 01, 2022 (last updated November 08, 2023)
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.
Attacker Value
Unknown

CVE-2022-22483

Disclosure Date: September 12, 2022 (last updated February 24, 2025)
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.
Attacker Value
Unknown

CVE-2022-35637

Disclosure Date: September 12, 2022 (last updated October 08, 2023)
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement into the Db2expln tool. IBM X-Force ID: 230823.
Attacker Value
Unknown

CVE-2022-34151

Disclosure Date: July 04, 2022 (last updated February 24, 2025)
Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studio' all models V1.49 and earlier, and Programmable Terminal (PT) NA series NA5-15W/NA5-12W/NA5-9W/NA5-7W models Runtime V1.15 and earlier, which may allow a remote attacker who successfully obtained the user credentials by analyzing the affected product to access the controller.
Attacker Value
Unknown

CVE-2022-33971

Disclosure Date: July 04, 2022 (last updated February 24, 2025)
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which may allow an adjacent attacker who can analyze the communication between the controller and the specific software used by OMRON internally to cause a denial-of-service (DoS) condition or execute a malicious program.