Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2024-01-19 CVE-2023-50963 Unspecified vulnerability in IBM Storage Defender Data Protect 1.4.1
IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.
network
low complexity
ibm
5.4
2024-01-19 CVE-2023-35020 Unspecified vulnerability in IBM Sterling Control Center 6.3.0
IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm
5.3
2024-01-19 CVE-2023-38738 Unspecified vulnerability in IBM Openpages With Watson 9.0
IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication.
network
low complexity
ibm
8.1
2024-01-19 CVE-2023-40683 Unspecified vulnerability in IBM Openpages With Watson 9.0
IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks.
network
low complexity
ibm
8.8
2024-01-18 CVE-2024-22317 Unspecified vulnerability in IBM APP Connect Enterprise
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of service due to improper restriction of excessive authentication attempts.
network
low complexity
ibm
critical
9.1
2024-01-17 CVE-2023-50950 Unspecified vulnerability in IBM Qradar Security Information and Event Manager 7.5.0
IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules.
network
low complexity
ibm
5.3
2024-01-11 CVE-2023-31001 Unspecified vulnerability in IBM products
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user.
local
low complexity
ibm
5.5
2024-01-11 CVE-2023-31003 Link Following vulnerability in IBM products
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls.
local
low complexity
ibm CWE-59
7.8
2024-01-11 CVE-2023-38267 Unspecified vulnerability in IBM products
IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed.
local
low complexity
ibm
5.5
2024-01-11 CVE-2023-45169 Unspecified vulnerability in IBM AIX and Vios
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of service.
local
low complexity
ibm
5.5