Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2023-32331

Disclosure Date: March 04, 2024 (last updated February 01, 2025)
IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979.
Attacker Value
Unknown

CVE-2023-29260

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 252135.
Attacker Value
Unknown

CVE-2023-29259

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute. IBM X-Force ID: 252055.
Attacker Value
Unknown

CVE-2021-38933

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210574.