Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2023-08-16 CVE-2023-35011 Server-Side Request Forgery (SSRF) vulnerability in IBM Cognos Analytics
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
5.4
2023-08-16 CVE-2023-35893 OS Command Injection vulnerability in IBM Security Guardium
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
network
low complexity
ibm CWE-78
8.8
2023-08-16 CVE-2023-38737 Resource Exhaustion vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by sending a specially-crafted request.
network
low complexity
ibm CWE-400
7.5
2023-08-14 CVE-2023-38721 Unspecified vulnerability in IBM I
The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability.
local
low complexity
ibm
7.8
2023-08-14 CVE-2023-38741 Unspecified vulnerability in IBM Txseries for Multiplatform 8.1/8.2/9.1
IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations.
network
low complexity
ibm
7.5
2023-08-02 CVE-2022-40609 Deserialization of Untrusted Data vulnerability in IBM SDK
IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw.
network
low complexity
ibm CWE-502
critical
9.8
2023-08-02 CVE-2023-23476 Unspecified vulnerability in IBM products
IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes.
network
low complexity
ibm
6.5
2023-07-31 CVE-2020-4868 Information Exposure Through an Error Message vulnerability in IBM Tririga Application Platform
IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
5.3
2023-07-31 CVE-2023-22595 Cross-site Scripting vulnerability in IBM products
IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-07-31 CVE-2023-24971 Deserialization of Untrusted Data vulnerability in IBM products
IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects.
network
low complexity
ibm CWE-502
6.5