Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2024-43191
Disclosure Date: September 26, 2024 (last updated September 27, 2024)
IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.
0
Attacker Value
Unknown
CVE-2023-46175
Disclosure Date: September 26, 2024 (last updated September 27, 2024)
IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user.
0
Attacker Value
Unknown
CVE-2022-42438
Disclosure Date: February 08, 2023 (last updated November 08, 2023)
IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210.
0
Attacker Value
Unknown
CVE-2021-38941
Disclosure Date: June 29, 2022 (last updated October 07, 2023)
IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 211048.
0
Attacker Value
Unknown
CVE-2020-4765
Disclosure Date: May 18, 2021 (last updated February 22, 2025)
IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 188902.
0
Attacker Value
Unknown
CVE-2021-20341
Disclosure Date: March 08, 2021 (last updated November 28, 2024)
IBM Cloud Pak for Multicloud Management Monitoring 2.2 returns potentially sensitive information in headers which could lead to further attacks against the system. IBM X-Force ID: 194513.
0