Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2021-05-24 CVE-2021-20389 Insufficiently Protected Credentials vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user.
local
low complexity
ibm CWE-522
2.1
2021-05-19 CVE-2021-20528 Cross-site Scripting vulnerability in IBM Control Center 6.2.0.0
IBM Control Center 6.2.0.0 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2021-05-19 CVE-2021-20374 Cross-site Scripting vulnerability in IBM Maximo Asset Management 7.6.0/7.6.1
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting.
network
ibm CWE-79
3.5
2021-05-19 CVE-2020-4765 Insecure Storage of Sensitive Information vulnerability in IBM Cloud PAK for Multicloud Management
IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
2.1
2021-05-14 CVE-2021-20391 Insecure Storage of Sensitive Information vulnerability in IBM Qradar User Behavior Analytics 1.0.0/4.1.0
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
2.1
2021-05-11 CVE-2020-4535 Cross-site Scripting vulnerability in IBM Openpages GRC Platform
IBM OpenPages GRC Platform 8.1 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2021-05-10 CVE-2021-20559 Cross-site Scripting vulnerability in IBM Control Desk 7.6.1.2/7.6.1.3
IBM Control Desk 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2021-05-05 CVE-2020-4929 Cross-site Scripting vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2021-05-04 CVE-2020-4987 Cross-site Scripting vulnerability in IBM Flashsystem 900 Firmware 1.4
The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and prior and 1.6.1.2 and prior.
network
ibm CWE-79
3.5
2021-04-27 CVE-2021-20550 Cross-site Scripting vulnerability in IBM Content Navigator 3.0.0
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5