Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2019-12-12 CVE-2019-4606 Untrusted Search Path vulnerability in IBM DB2 High Performance Unload Load
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability.
local
low complexity
ibm CWE-426
7.8
2019-12-11 CVE-2019-4715 OS Command Injection vulnerability in IBM Spectrum Scale
IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system.
network
low complexity
ibm CWE-78
8.8
2019-12-09 CVE-2019-4612 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Planning Analytics 2.0
IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal.
network
low complexity
ibm CWE-434
8.8
2019-12-03 CVE-2019-4130 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cloud PAK System 2.3/2.3.0.1
IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
network
low complexity
ibm CWE-434
8.8
2019-11-26 CVE-2019-4387 SQL Injection vulnerability in IBM Sterling B2B Integrator 6.0.0.0/6.0.0.1/6.0.2.0
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8
2019-11-20 CVE-2019-4561 Deserialization of Untrusted Data vulnerability in IBM Security Identity Manager 6.0.0
IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data.
network
low complexity
ibm CWE-502
8.8
2019-11-12 CVE-2019-4652 Incorrect Default Permissions vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions.
local
low complexity
ibm CWE-276
7.1
2019-11-09 CVE-2018-1721 XML Injection (aka Blind XPath Injection) vulnerability in IBM Cognos Analytics 11.0.0/11.1.0
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-91
8.8
2019-10-29 CVE-2019-4546 Improper Privilege Management vulnerability in IBM products
After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allowed to access.
network
low complexity
ibm CWE-269
8.8
2019-10-29 CVE-2019-4339 Inadequate Encryption Strength vulnerability in IBM Security Guardium BIG Data Intelligence 4.0
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5