Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2020-03-31 CVE-2020-4237 Cross-Site Request Forgery (CSRF) vulnerability in IBM Tivoli Netcool/Impact
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2020-03-31 CVE-2020-4214 Improper Input Validation vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-20
7.5
2020-03-31 CVE-2020-4206 OS Command Injection vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-78
8.8
2020-03-26 CVE-2020-4276 Unspecified vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector.
network
high complexity
ibm
7.5
2020-03-24 CVE-2020-4253 Insufficient Session Expiration vulnerability in IBM Content Navigator 3.0.0
IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
network
low complexity
ibm CWE-613
8.8
2020-03-24 CVE-2019-4553 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM API Connect
IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
7.5
2020-03-09 CVE-2020-4217 Improper Check for Unusual or Exceptional Conditions vulnerability in IBM Spectrum Scale
The IBM Spectrum Scale 4.2 and 5.0 file system component is affected by a denial of service security vulnerability.
network
low complexity
ibm CWE-754
7.5
2020-03-05 CVE-2020-4278 Incorrect Permission Assignment for Critical Resource vulnerability in IBM products
IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges due to weak file permissions when specific debug settings are enabled in a Linux or Unix enviornment.
local
low complexity
ibm CWE-732
7.8
2020-03-02 CVE-2020-4283 Use of Hard-coded Credentials vulnerability in IBM Security Information Queue
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
network
low complexity
ibm CWE-798
8.6
2020-02-25 CVE-2019-4557 Inadequate Encryption Strength vulnerability in IBM Qradar Advisor 1.1/2.5.0
IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5