Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2025-01-31 CVE-2024-40696 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2025-01-31 CVE-2024-45089 Information Exposure Through Discrepancy vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information due to an observable discrepancy.
network
low complexity
ibm CWE-203
4.3
2025-01-31 CVE-2024-47103 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2025-01-31 CVE-2024-47116 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2025-01-31 CVE-2024-49807 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2025-01-29 CVE-2023-35907 Weak Password Requirements vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2025-01-29 CVE-2023-37398 Weak Password Requirements vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2025-01-29 CVE-2023-37412 Execution with Unnecessary Privileges vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
network
low complexity
ibm CWE-250
4.9
2025-01-29 CVE-2023-37413 Response Discrepancy Information Exposure vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
network
low complexity
ibm CWE-204
5.3
2025-01-29 CVE-2023-33838 Use of a One-Way Hash without a Salt vulnerability in IBM Security Verify Governance 10.0.2
IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
network
low complexity
ibm CWE-759
4.9