Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2022-11-21 CVE-2022-40746 Uncontrolled Search Path Element vulnerability in IBM I Access Client Solutions
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability.
local
high complexity
ibm CWE-427
6.7
2022-11-17 CVE-2022-38390 Cross-site Scripting vulnerability in IBM Business Automation Workflow
Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2022-11-17 CVE-2022-40751 Insufficiently Protected Credentials vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 could allow a user with administrative privileges including "Manage Security" permissions may be able to recover a credential previously saved for performing authenticated LDAP searches.  IBM X-Force ID:   236601.
network
low complexity
ibm CWE-522
4.9
2022-11-16 CVE-2022-40752 Command Injection vulnerability in IBM products
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements.
network
low complexity
ibm CWE-77
critical
9.8
2022-11-16 CVE-2022-34354 Insecure Storage of Sensitive Information vulnerability in IBM Partner Engagement Manager 6.1.2/6.2.0/6.2.1
IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2022-11-15 CVE-2022-38385 Improper Input Validation vulnerability in IBM Cloud PAK for Security 1.10.0.0/1.10.2.0
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation.
network
low complexity
ibm CWE-20
8.1
2022-11-15 CVE-2022-40753 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2022-11-14 CVE-2022-34317 Cross-site Scripting vulnerability in IBM Cics TX 11.1
IBM CICS TX 11.1 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2022-11-14 CVE-2022-34320 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Cics TX 11.1
IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
7.5
2022-11-14 CVE-2022-34314 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Cics TX 11.1
IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission settings.
local
low complexity
ibm CWE-732
3.3