Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-01 CVE-2021-29740 Use of Externally-Controlled Format String vulnerability in IBM Spectrum Scale
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability.
local
low complexity
ibm CWE-134
7.8
2021-05-26 CVE-2019-4588 Uncontrolled Search Path Element vulnerability in IBM DB2
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks.
local
low complexity
ibm CWE-427
7.8
2021-05-26 CVE-2021-20492 XXE vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
8.2
2021-05-24 CVE-2020-4990 SQL Injection vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8
2021-05-24 CVE-2021-20385 Unspecified vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system.
network
low complexity
ibm
7.2
2021-05-24 CVE-2021-20389 Insufficiently Protected Credentials vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user.
local
low complexity
ibm CWE-522
7.8
2021-05-24 CVE-2021-20419 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
7.5
2021-05-24 CVE-2021-20557 OS Command Injection vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
network
low complexity
ibm CWE-78
7.2
2021-05-20 CVE-2020-4850 Improper Encoding or Escaping of Output vulnerability in IBM Gpfs.Tct.Server
IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the leftover files after configuration.
network
low complexity
ibm CWE-116
7.5
2021-05-20 CVE-2021-29686 Unspecified vulnerability in IBM Security Identity Manager 7.0.2
IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to.
network
low complexity
ibm
8.8