Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Very High

CVE-2013-3018

Disclosure Date: May 24, 2018 (last updated November 26, 2024)
The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct request, as demonstrated by happyaxis.jsp. IBM X-Force ID: 84354.
0
Attacker Value
Unknown

CVE-2025-23227

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2023-47142

Disclosure Date: February 02, 2024 (last updated February 09, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267.
Attacker Value
Unknown

CVE-2023-47144

Disclosure Date: February 02, 2024 (last updated February 09, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 270271.
Attacker Value
Unknown

CVE-2023-47143

Disclosure Date: February 02, 2024 (last updated February 09, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 270270.
Attacker Value
Unknown

CVE-2018-1675

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are configured to use TADDM. IBM X-Force ID: 145110.
0
Attacker Value
Unknown

CVE-2018-1455

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 11029.
0
Attacker Value
Unknown

CVE-2013-3017

Disclosure Date: July 09, 2018 (last updated November 27, 2024)
IBM Tivoli Application Dependency Discovery Manager (TADDM) before 7.2.1.5 and 7.2.x before 7.2.2 make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging support for weak SSL ciphers. IBM X-Force ID: 84353.
0
Attacker Value
Unknown

CVE-2013-3023

Disclosure Date: May 24, 2018 (last updated November 26, 2024)
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used. IBM X-Force ID: 84361.
0
Attacker Value
Unknown

CVE-2013-4040

Disclosure Date: May 01, 2018 (last updated November 26, 2024)
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2.x before 7.2.1.5 and 7.2.x before 7.2.2.0 on Unix use weak permissions (755) for unspecified configuration and log files, which allows local users to obtain sensitive information by reading the files. IBM X-Force ID: 86176.
0