Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2024-40697 Weak Password Requirements vulnerability in IBM Common Licensing 9.0
IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
7.5
2024-07-30 CVE-2022-33167 Incorrect Permission Assignment for Critical Resource vulnerability in IBM products
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag.
network
low complexity
ibm CWE-732
7.5
2024-07-25 CVE-2022-32759 Unspecified vulnerability in IBM products
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information.
network
low complexity
ibm
7.5
2024-07-18 CVE-2023-50304 Unspecified vulnerability in IBM products
IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm
8.2
2024-07-15 CVE-2024-39731 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Datacap
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
7.5
2024-07-14 CVE-2024-39732 Cleartext Storage of Sensitive Information vulnerability in IBM Datacap
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious user.
network
low complexity
ibm CWE-312
7.5
2024-07-09 CVE-2024-35154 Unspecified vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code.
network
low complexity
ibm
7.2
2024-07-08 CVE-2024-39743 Unspecified vulnerability in IBM MQ Operator
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service caused by incorrect memory de-allocation.
network
low complexity
ibm
7.5
2024-07-08 CVE-2024-38330 Unspecified vulnerability in IBM I 7.2/7.3/7.4
IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call.
local
low complexity
ibm
7.8
2024-06-30 CVE-2024-31902 Unspecified vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm
8.8