VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2020-4765LowMay 19, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 188902.

  • CVE-2021-20391LowMay 14, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 195999.

  • CVE-2021-29671LowApr 9, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Spectrum Scale 5.1.0.1 could allow a local attacker to bypass the filesystem audit logging mechanism when file audit logging is enabled. IBM X-Force ID: 199478.

  • CVE-2020-4726LowMar 2, 2021
    risk 0.21cvss 3.3epss 0.00

    The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975.

  • CVE-2020-4889LowJan 26, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190971.

  • CVE-2020-4906LowDec 16, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2020-4886LowNov 13, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system. IBM X-Force ID: 190910.

  • CVE-2020-4650LowNov 9, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.

  • CVE-2020-4629LowSep 30, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.

  • CVE-2020-4344LowSep 15, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247.

  • CVE-2020-4591LowAug 28, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted container pool. IBM X-Force ID: 184746.

  • CVE-2019-4695LowAug 26, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 171926.

  • CVE-2020-4371LowJul 22, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains sensitive information in leftover debug code that could be used aid a local user in further attacks against the system. IBM X-Force ID: 179008.

  • CVE-2020-4345LowMay 17, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.

  • CVE-2019-4465LowDec 3, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Pak System 2.3 and 2.3.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 163774.

  • CVE-2019-4395LowOct 25, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a local user to obtain sensitive information from temporary script files. IBM X-Force ID: 162333.

  • CVE-2019-4398LowOct 24, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.

  • CVE-2019-4112LowSep 30, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158105.

  • CVE-2019-4132LowAug 29, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Automation Manager 3.1.2 could allow a user to be impropertly redirected and obtain sensitive information rather than receive a 404 error message. IBM X-Force ID: 158274.

  • CVE-2019-4054LowJul 17, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could aid an attacker in further attacks against the system. IBM X-Force ID: 156563.

  • CVE-2019-4296LowJul 1, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759.

  • CVE-2019-4177LowJun 17, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158882.

  • CVE-2019-4174LowJun 17, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158879.

  • CVE-2019-4218LowJun 6, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 159227.

  • CVE-2019-4161LowJun 6, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 158660.

  • CVE-2018-2005LowMay 20, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local attacker with elevated permissions. IBM X-Force ID: 155007

  • CVE-2019-4207LowMay 7, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available to a local user that could be used in further attacks against the system. IBM X-Force ID: 159148.

  • CVE-2016-0205LowAug 30, 2018
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacker after authentication to enumerate valid users of the system. IBM X-Force ID: 109394.

  • CVE-2015-5045LowMar 26, 2018
    risk 0.21cvss 3.3epss 0.00

    The Administration and Reporting tool in IBM Rational License Key Server (RLKS) before 8.1.4.9 iFix 04 allows local users to obtain sensitive information via unspecified vectors. IBM X-Force ID: 106938.

  • CVE-2015-7449LowMar 20, 2018
    risk 0.21cvss 3.3epss 0.00

    IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2…

  • CVE-2016-0275LowMar 9, 2018
    risk 0.21cvss 3.3epss 0.00

    IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate…

  • CVE-2017-1681LowJan 11, 2018
    risk 0.21cvss 3.3epss 0.00

    IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitive information, caused by improper handling of application requests, which could allow unauthorized access to read a file. IBM X-Force ID: 134003.

  • CVE-2017-1478LowJan 11, 2018
    risk 0.21cvss 3.3epss 0.00

    IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613.

  • CVE-2017-1699LowJan 4, 2018
    risk 0.21cvss 3.3epss 0.00

    IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.

  • CVE-2017-1270LowDec 20, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 124745.

  • CVE-2017-1261LowDec 20, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736.

  • CVE-2017-1716LowDec 13, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Tivoli Workload Scheduler 8.6.0, 9.1.0, and 9.2.0 could disclose sensitive information to a local attacker due to improper permission settings. IBM X-Force ID: 134638.

  • CVE-2016-2978LowAug 29, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.

  • CVE-2016-2974LowAug 29, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.

  • CVE-2017-1422LowAug 22, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications which could disclose sensitive information. IBM X-Force ID: 127412.

  • CVE-2017-1381LowJul 21, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152.

  • CVE-2017-1176LowJul 5, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299.

  • CVE-2017-1125LowJun 7, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.

  • CVE-2016-0206LowFeb 8, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially crafted and malformed URL.

  • CVE-2016-0202LowFeb 8, 2017
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the current users domain.

  • CVE-2016-5938LowFeb 1, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2016-0394LowFeb 1, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.

  • CVE-2016-0296LowFeb 1, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.

  • CVE-2016-2877LowNov 30, 2016
    risk 0.21cvss 3.3epss 0.00

    IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file.

  • CVE-2016-2949LowNov 30, 2016
    risk 0.21cvss 3.3epss 0.00

    IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.

Page 119 of 177