Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2023-44487
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
1
Attacker Value
Unknown
CVE-2024-38325
Disclosure Date: January 27, 2025 (last updated February 27, 2025)
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI
could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
0
Attacker Value
Unknown
CVE-2024-52361
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
stores user credentials in plain text which can be read by an authenticated user with access to the pod.
0
Attacker Value
Unknown
CVE-2024-47119
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client.
0
Attacker Value
Unknown
CVE-2023-50956
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.
0
Attacker Value
Unknown
CVE-2024-38324
Disclosure Date: September 25, 2024 (last updated February 26, 2025)
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.
0
Attacker Value
Unknown
CVE-2024-38322
Disclosure Date: June 28, 2024 (last updated February 26, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869.
0
Attacker Value
Unknown
CVE-2024-25031
Disclosure Date: June 28, 2024 (last updated February 26, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute force account credentials. IBM X-Force ID: 281678.
0
Attacker Value
Unknown
CVE-2024-27261
Disclosure Date: April 12, 2024 (last updated February 26, 2025)
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. IBM X-Force ID: 283986.
0
Attacker Value
Unknown
CVE-2024-22313
Disclosure Date: February 10, 2024 (last updated February 26, 2025)
IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 278749.
0