Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2023-26024

Disclosure Date: December 01, 2023 (last updated February 25, 2025)
IBM Planning Analytics on Cloud Pak for Data 4.0 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication. IBM X-Force ID: 247898.
Attacker Value
Unknown

CVE-2023-27877

Disclosure Date: July 19, 2023 (last updated February 25, 2025)
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
Attacker Value
Unknown

CVE-2023-26026

Disclosure Date: July 19, 2023 (last updated February 25, 2025)
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
Attacker Value
Unknown

CVE-2023-26023

Disclosure Date: July 19, 2023 (last updated February 25, 2025)
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
Attacker Value
Unknown

CVE-2023-28958

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.
Attacker Value
Unknown

CVE-2023-30444

Disclosure Date: April 27, 2023 (last updated February 24, 2025)
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.
Attacker Value
Unknown

CVE-2022-41297

Disclosure Date: December 01, 2022 (last updated February 24, 2025)
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.