Vulnerabilities > IBM > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-12-25 CVE-2024-39727 Unspecified vulnerability in IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2/7.0.3
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site.
network
low complexity
ibm
critical
9.8
2024-12-03 CVE-2024-25020 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cognos Controller 11.0.0/11.0.1
IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry page.
network
low complexity
ibm CWE-434
critical
9.8
2024-12-03 CVE-2024-25019 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cognos Controller 11.0.0/11.0.1
IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments.
network
low complexity
ibm CWE-434
critical
9.8
2024-12-03 CVE-2024-40691 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cognos Controller 11.0.0/11.0.1
IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.
network
low complexity
ibm CWE-434
critical
9.8
2024-10-22 CVE-2024-43177 Improper Certificate Validation vulnerability in IBM Concert 1.0.0/1.0.1
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
network
low complexity
ibm CWE-295
critical
9.8
2024-09-04 CVE-2024-45076 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Webmethods Integration 10.15
IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system.
network
low complexity
ibm CWE-434
critical
9.9
2024-08-31 CVE-2024-39747 Unspecified vulnerability in IBM Sterling Connect Direct web Services
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.
network
low complexity
ibm
critical
9.8
2024-08-16 CVE-2022-33162 Unspecified vulnerability in IBM products
IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources, at the privilege level of a standard unprivileged user.
network
low complexity
ibm
critical
9.8
2024-08-04 CVE-2024-35143 Missing Authentication for Critical Function vulnerability in IBM products
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server.
network
low complexity
ibm CWE-306
critical
9.1
2024-07-26 CVE-2024-40689 Unspecified vulnerability in IBM products
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection.
network
low complexity
ibm
critical
9.8