Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2024-05-14 CVE-2024-28761 Cross-site Scripting vulnerability in IBM APP Connect Enterprise
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection.
network
low complexity
ibm CWE-79
5.4
2024-05-14 CVE-2024-28781 Unspecified vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting.
network
low complexity
ibm
5.4
2024-05-14 CVE-2024-22343 Unspecified vulnerability in IBM Txseries for Multiplatform 8.2
IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm
3.3
2024-05-14 CVE-2024-22344 Cross-site Scripting vulnerability in IBM Txseries for Multiplatform 8.2
IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection.
network
low complexity
ibm CWE-79
6.1
2024-05-14 CVE-2024-22345 Unspecified vulnerability in IBM Txseries for Multiplatform 8.2
IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
network
low complexity
ibm
7.5
2024-05-14 CVE-2023-47709 Unspecified vulnerability in IBM Security Guardium
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
network
low complexity
ibm
8.8
2024-05-14 CVE-2023-47711 Unspecified vulnerability in IBM Security Guardium
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service.
network
low complexity
ibm
6.5
2024-05-04 CVE-2023-27283 Information Exposure Through Discrepancy vulnerability in IBM Aspera Orchestrator 4.0.1
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies.
network
low complexity
ibm CWE-203
5.3
2024-05-03 CVE-2021-20451 Unspecified vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection.
network
low complexity
ibm
7.2
2024-05-03 CVE-2022-22364 Authentication Bypass by Spoofing vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-290
5.3