Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2020-02-12 CVE-2019-4427 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Cloud CLI
IBM Cloud CLI 0.6.0 through 0.16.1 windows installers are signed using SHA1 certificate.
network
low complexity
ibm CWE-327
7.5
2020-02-11 CVE-2013-0517 OS Command Injection vulnerability in IBM Sterling External Authentication Server
A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malicious user execute arbitrary code.
local
low complexity
ibm CWE-78
7.8
2020-02-05 CVE-2015-0102 Improper Authentication vulnerability in IBM Workflow
IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
network
low complexity
ibm CWE-287
8.1
2020-02-05 CVE-2019-4613 Cross-Site Request Forgery (CSRF) vulnerability in IBM Planning Analytics 2.0
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2020-02-05 CVE-2013-0507 Session Fixation vulnerability in IBM Infosphere Information Server
IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
network
low complexity
ibm CWE-384
8.1
2020-02-04 CVE-2020-4163 Unspecified vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed.
network
low complexity
ibm
7.2
2020-02-04 CVE-2019-4541 Unspecified vulnerability in IBM Security Directory Server
IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity.
network
low complexity
ibm
7.2
2020-02-04 CVE-2019-4540 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Security Directory Server
IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
7.5
2020-01-31 CVE-2019-4720 Allocation of Resources Without Limits or Throttling vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request.
network
low complexity
ibm CWE-770
7.5
2020-01-28 CVE-2019-4707 XXE vulnerability in IBM Security Access Manager 9.0.7.0
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1