Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2022-04-08 CVE-2020-4668 Cross-Site Request Forgery (CSRF) vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2022-04-08 CVE-2022-22339 Server-Side Request Forgery (SSRF) vulnerability in IBM Planning Analytics 2.0
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
7.3
2022-04-06 CVE-2022-22410 Unspecified vulnerability in IBM Watson Query
IBM Watson Query with Cloud Pak for Data as a Service could allow an authenticated user to obtain sensitive information that would allow them to examine or alter system configurations or data sources connected to the service.
network
low complexity
ibm
7.2
2022-04-01 CVE-2022-22327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
7.5
2022-04-01 CVE-2022-22331 Authorization Bypass Through User-Controlled Key vulnerability in IBM Partner Engagement Manager 6.2.0
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR).
network
low complexity
ibm CWE-639
7.1
2022-04-01 CVE-2022-22332 Operation on a Resource after Expiration or Release vulnerability in IBM Partner Engagement Manager 6.2.0
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token.
network
low complexity
ibm CWE-672
7.5
2022-03-21 CVE-2022-22394 Unspecified vulnerability in IBM Spectrum Protect 8.1.14.100
The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls.
network
low complexity
ibm
8.8
2022-03-14 CVE-2022-22346 Cross-Site Request Forgery (CSRF) vulnerability in IBM Spectrum Protect Operations Center
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2022-03-14 CVE-2022-22354 Unspecified vulnerability in IBM products
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place.
network
low complexity
ibm
7.5
2022-03-10 CVE-2021-39022 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Guardium Data Encryption 4.0.0.0/5.0.0.0
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.
network
low complexity
ibm CWE-1236
8.8