VYPR

Daeja ViewONE Virtual

by IBM

CVEs (5)

  • CVE-2017-1210HigOct 24, 2017
    risk 0.49cvss 7.5epss 0.01

    IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to look legitimate. IBM X-Force ID: 123850.

  • CVE-2017-1308MedJul 13, 2017
    risk 0.42cvss 6.5epss 0.02

    IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.

  • CVE-2019-4246MedOct 1, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM Daeja ViewONE Virtual 5.0 through 5.0.6 could expose internal parameters to ViewONE clients that could be used in further attacks against the system. IBM X-Force ID: 159521.

  • CVE-2023-40684MedOct 4, 2023
    risk 0.30cvss 4.6epss 0.00

    IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…

  • CVE-2017-1211LowOct 24, 2017
    risk 0.16cvss 2.5epss 0.00

    IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled. IBM X-Force ID: 123851.