Transformation Extender Advanced
by IBM
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49881 | Med | 0.41 | 6.3 | 0.00 | Oct 1, 2025 | IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | ||
| CVE-2023-49883 | Med | 0.38 | 5.9 | 0.00 | Oct 1, 2025 | IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | ||
| CVE-2023-50300 | Med | 0.33 | 5.1 | 0.00 | Oct 1, 2025 | IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls. | ||
| CVE-2021-29883 | Med | 0.28 | 4.3 | 0.01 | Oct 21, 2021 | IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site… | ||
| CVE-2023-50301 | Low | 0.12 | 1.9 | 0.00 | Oct 1, 2025 | IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user. |
- risk 0.41cvss 6.3epss 0.00
IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
- risk 0.38cvss 5.9epss 0.00
IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
- risk 0.33cvss 5.1epss 0.00
IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls.
- risk 0.28cvss 4.3epss 0.01
IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site…
- risk 0.12cvss 1.9epss 0.00
IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user.