Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2019-03-11 CVE-2018-1890 Uncontrolled Search Path Element vulnerability in IBM SDK 8.0
IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users.
local
low complexity
ibm CWE-427
7.8
2019-02-21 CVE-2018-1946 Inadequate Encryption Strength vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
network
low complexity
ibm CWE-326
7.5
2019-02-15 CVE-2018-1701 Unspecified vulnerability in IBM products
IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server.
network
high complexity
ibm
8.5
2019-02-15 CVE-2017-1695 Inadequate Encryption Strength vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2019-02-04 CVE-2018-1970 XXE vulnerability in IBM Security Access Manager
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2019-02-04 CVE-2018-1675 Information Exposure vulnerability in IBM Tivoli Application Dependency Discovery Manager
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are configured to use TADDM.
network
low complexity
ibm CWE-200
7.5
2019-01-29 CVE-2018-1668 Improper Authentication vulnerability in IBM Datapower Gateway
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information.
network
low complexity
ibm CWE-287
7.5
2019-01-24 CVE-2018-1959 Use of Hard-coded Credentials vulnerability in IBM Security Identity Manager
IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
local
low complexity
ibm CWE-798
7.8
2019-01-23 CVE-2018-1751 Inadequate Encryption Strength vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2019-01-18 CVE-2018-2019 XXE vulnerability in IBM Security Identity Manager
IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1