Show filters
277 Total Results
Displaying 81-90 of 277
Sort by:
Attacker Value
Unknown
CVE-2020-4840
Disclosure Date: December 16, 2020 (last updated February 22, 2025)
IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 190044.
0
Attacker Value
Unknown
CVE-2020-4843
Disclosure Date: December 16, 2020 (last updated February 22, 2025)
IBM Security Secret Server 10.6 stores potentially sensitive information in config files that could be read by an authenticated user. IBM X-Force ID: 190048.
0
Attacker Value
Unknown
CVE-2020-8755
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Race condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
0
Attacker Value
Unknown
CVE-2020-8705
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.
0
Attacker Value
Unknown
CVE-2020-8744
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2019-4547
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 165949.
0
Attacker Value
Unknown
CVE-2019-4563
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 166624.
0
Attacker Value
Unknown
CVE-2020-4324
Disclosure Date: September 23, 2020 (last updated February 22, 2025)
IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improper input validation. IBM X-Force ID: 177515.
0
Attacker Value
Unknown
CVE-2020-4340
Disclosure Date: September 23, 2020 (last updated February 22, 2025)
IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate validation. IBM X-Force ID: 178180.
0
Attacker Value
Unknown
CVE-2020-5622
Disclosure Date: September 02, 2020 (last updated February 22, 2025)
Shadankun Server Security Type (excluding normal blocking method types) Ver.1.5.3 and earlier allows remote attackers to cause a denial of service which may result in not being able to add newly detected attack source IP addresses as blocking targets for about 10 minutes via a specially crafted request.
0