Vulnerabilities > IBM > Cloud PAK System > 2.3.0.1

DATE CVE VULNERABILITY TITLE RISK
2022-05-09 CVE-2021-20479 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
5.0
2021-01-04 CVE-2020-4928 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files.
local
low complexity
ibm CWE-434
4.6
2021-01-04 CVE-2020-4919 Improper Privilege Management vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to impersonate another user on the system.
network
low complexity
ibm CWE-269
5.5
2021-01-04 CVE-2020-4918 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct object reference in sell service console for the Platform System Manager.
local
low complexity
ibm CWE-434
2.1
2021-01-04 CVE-2020-4917 Cross-Site Request Forgery (CSRF) vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
ibm CWE-352
6.8
2021-01-04 CVE-2020-4916 Cross-site Scripting vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2021-01-04 CVE-2020-4913 Insufficiently Protected Credentials vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user.
local
low complexity
ibm CWE-522
2.1
2021-01-04 CVE-2020-4912 Improper Privilege Management vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user.
network
low complexity
ibm CWE-269
6.5
2021-01-04 CVE-2020-4910 Cross-site Scripting vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2021-01-04 CVE-2020-4909 Cross-site Scripting vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5