Vulnerabilities > IBM > AIX

DATE CVE VULNERABILITY TITLE RISK
2020-03-16 CVE-2019-4619 Information Exposure Through an Error Message vulnerability in IBM MQ, MQ Appliance and Websphere MQ
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.
local
low complexity
ibm hp linux microsoft oracle CWE-209
2.1
2020-02-12 CVE-2019-4741 Server-Side Request Forgery (SSRF) vulnerability in IBM Content Navigator 3.0.0
IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF).
network
low complexity
ibm linux microsoft CWE-918
5.0
2019-01-23 CVE-2018-1751 Inadequate Encryption Strength vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm linux microsoft CWE-326
5.0
2019-01-17 CVE-2018-20733 XXE vulnerability in SAS web Infrastructure Platform 9.4
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
network
low complexity
sas hpe ibm linux microsoft oracle CWE-611
5.0
2019-01-17 CVE-2018-20732 Deserialization of Untrusted Data vulnerability in SAS web Infrastructure Platform 9.4
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
network
low complexity
sas hpe ibm linux microsoft oracle CWE-502
7.5
2019-01-17 CVE-2015-9281 Cross-site Scripting vulnerability in SAS web Infrastructure Platform 9.4
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.
4.3
2018-06-22 CVE-2018-1655 Information Exposure vulnerability in IBM AIX
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory.
local
low complexity
ibm CWE-200
2.1
2018-04-03 CVE-2018-8049 Improper Input Validation vulnerability in Unisys Stealth SVG 2.8
The Stealth endpoint in Unisys Stealth SVG 2.8.x, 3.0.x before 3.0.1999, 3.1.x, 3.2.x before 3.2.030, and 3.3.x before 3.3.016, when running on Linux and AIX, allows remote attackers to cause a denial of service (crash) via crafted packets.
network
low complexity
unisys ibm linux CWE-20
5.0
2018-02-13 CVE-2018-1383 Unspecified vulnerability in IBM AIX
A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine.
network
low complexity
ibm
critical
9.0
2018-02-07 CVE-2017-1692 Unspecified vulnerability in IBM AIX
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.
local
low complexity
ibm
7.2