Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown
CVE-2023-47716
Disclosure Date: March 01, 2024 (last updated March 01, 2024)
IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual circumstances. IBM X-Force ID: 271656.
0
Attacker Value
Unknown
CVE-2023-38366
Disclosure Date: March 01, 2024 (last updated March 01, 2024)
IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 261115.
0
Attacker Value
Unknown
CVE-2023-35905
Disclosure Date: October 04, 2023 (last updated February 25, 2025)
IBM FileNet Content Manager 5.5.8, 5.5.10, and 5.5.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 259384.
0
Attacker Value
Unknown
CVE-2021-38965
Disclosure Date: January 14, 2022 (last updated February 23, 2025)
IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346.
0
Attacker Value
Unknown
CVE-2020-4759
Disclosure Date: November 06, 2020 (last updated February 22, 2025)
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736.
0
Attacker Value
Unknown
CVE-2020-4447
Disclosure Date: July 22, 2020 (last updated February 21, 2025)
IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181227.
0
Attacker Value
Unknown
CVE-2019-4572
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into a log file that could be accessed by an administrator on the local machine. IBM X-Force ID: 166798.
0
Attacker Value
Unknown
CVE-2018-1844
Disclosure Date: October 12, 2018 (last updated November 27, 2024)
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150904.
0
Attacker Value
Unknown
CVE-2018-1542
Disclosure Date: July 06, 2018 (last updated November 27, 2024)
IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.0 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 142597.
0
Attacker Value
Unknown
CVE-2018-1556
Disclosure Date: July 06, 2018 (last updated November 27, 2024)
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142893.
0