Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2023-04-07 CVE-2022-33959 Unspecified vulnerability in IBM Sterling Order Management 10
IBM Sterling Order Management 10.0 could allow a user to bypass validation and perform unauthorized actions on behalf of other users.
network
low complexity
ibm
8.1
2023-04-07 CVE-2023-27876 Unspecified vulnerability in IBM Tririga Application Platform 4.0
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data.
network
low complexity
ibm
7.1
2023-04-07 CVE-2022-34333 Unspecified vulnerability in IBM Sterling Order Management 10
IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm
7.5
2023-03-22 CVE-2022-43863 Improper Privilege Management vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities.
network
low complexity
ibm CWE-269
7.2
2023-03-22 CVE-2023-25924 Unspecified vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization.
network
low complexity
ibm
8.8
2023-03-21 CVE-2023-25923 Unspecified vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization.
network
low complexity
ibm
7.5
2023-03-21 CVE-2023-27871 SQL Injection vulnerability in IBM Aspera Faspex 4.4.1/4.4.2
IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query.
network
low complexity
ibm CWE-89
7.5
2023-03-21 CVE-2023-27874 Unspecified vulnerability in IBM Aspera Faspex 4.4.1/4.4.2
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data.
network
low complexity
ibm
8.8
2023-03-16 CVE-2023-27875 Unspecified vulnerability in IBM Aspera Faspex 5.0.4
IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls.
network
low complexity
ibm
7.5
2023-03-15 CVE-2020-4927 Unspecified vulnerability in IBM Spectrum Scale
A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol.
network
low complexity
ibm
8.2