Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2024-07-08 CVE-2024-38330 Uncontrolled Search Path Element vulnerability in IBM I 7.2/7.3/7.4
IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call.
local
low complexity
ibm CWE-427
7.8
2024-07-08 CVE-2024-39723 Improper Authentication vulnerability in IBM Storage Virtualize 8.6
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator.
low complexity
ibm CWE-287
4.6
2024-06-30 CVE-2023-50964 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-06-30 CVE-2024-28794 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-06-30 CVE-2023-50952 Server-Side Request Forgery (SSRF) vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
5.4
2024-06-30 CVE-2023-50953 Information Exposure Through an Error Message vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
network
low complexity
ibm CWE-209
4.3
2024-06-30 CVE-2024-28797 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-06-30 CVE-2024-31898 Authorization Bypass Through User-Controlled Key vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
network
low complexity
ibm CWE-639
5.4
2024-06-30 CVE-2023-50954 Unspecified vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system.
network
low complexity
ibm
5.3
2024-06-30 CVE-2024-28798 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
6.1