Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2021-11-02 CVE-2021-29737 Improper Certificate Validation vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate.
network
low complexity
ibm CWE-295
7.5
2021-11-02 CVE-2021-29875 Unspecified vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerability.
network
low complexity
ibm
7.5
2021-11-02 CVE-2021-29888 Cross-Site Request Forgery (CSRF) vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2021-10-27 CVE-2021-29774 Unspecified vulnerability in IBM products
IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations.
network
high complexity
ibm
7.5
2021-10-27 CVE-2021-29844 Server-Side Request Forgery (SSRF) vulnerability in IBM products
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
8.8
2021-10-21 CVE-2021-29873 Unspecified vulnerability in IBM products
IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability.
network
low complexity
ibm
8.1
2021-10-15 CVE-2021-29679 Code Injection vulnerability in multiple products
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive.
network
low complexity
ibm netapp CWE-94
8.8
2021-10-15 CVE-2021-29745 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to.
network
low complexity
ibm netapp
8.8
2021-10-12 CVE-2021-38862 Inadequate Encryption Strength vulnerability in IBM Data Risk Manager 2.0.6
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2021-10-07 CVE-2021-20489 Cross-Site Request Forgery (CSRF) vulnerability in IBM Sterling File Gateway
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8