Vulnerabilities > IBM > Daeja Viewone

DATE CVE VULNERABILITY TITLE RISK
2019-10-01 CVE-2019-4246 Unspecified vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Virtual 5.0 through 5.0.6 could expose internal parameters to ViewONE clients that could be used in further attacks against the system.
network
low complexity
ibm
5.3
2019-07-30 CVE-2019-4456 XXE vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2019-07-02 CVE-2019-4260 Unspecified vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 5.0 through 5.0.5 could allow an unauthorized user to download server files resulting in sensitive information disclosure.
network
low complexity
ibm
5.3
2018-11-02 CVE-2018-1835 XXE vulnerability in IBM Daeja Viewone 5.0
IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2018-02-27 CVE-2018-1399 Cross-site Scripting vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5 and 5.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-10-24 CVE-2017-1212 Unspecified vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of service when viewing or opening a large file.
network
low complexity
ibm
6.5
2017-10-24 CVE-2017-1211 Information Exposure vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled.
local
high complexity
ibm CWE-200
2.5
2017-10-24 CVE-2017-1210 Improper Input Validation vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to look legitimate.
network
low complexity
ibm CWE-20
7.5
2017-10-24 CVE-2017-1209 Cross-site Scripting vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-07-13 CVE-2017-1308 Files or Directories Accessible to External Parties vulnerability in IBM Daeja Viewone 4.1.5/4.1.5.1/5.0
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls.
network
low complexity
ibm CWE-552
6.5