Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2019-10-25 CVE-2019-4395 Unspecified vulnerability in IBM Cloud Orchestrator
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a local user to obtain sensitive information from temporary script files.
local
low complexity
ibm
2.1
2019-10-25 CVE-2019-4396 Injection vulnerability in IBM Cloud Orchestrator
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input.
network
ibm CWE-74
3.5
2019-10-25 CVE-2019-4461 Injection vulnerability in IBM Cloud Orchestrator
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content.
network
ibm CWE-74
3.5
2019-10-24 CVE-2019-4398 Missing Encryption of Sensitive Data vulnerability in IBM Cloud Orchestrator and Cloud Orchestrator Enterprise
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies.
local
low complexity
ibm CWE-311
2.1
2019-10-24 CVE-2019-4459 Cross-site Scripting vulnerability in IBM Cloud Orchestrator
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2019-10-24 CVE-2019-4486 Cross-site Scripting vulnerability in IBM products
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2019-10-14 CVE-2019-4572 Information Exposure Through Log Files vulnerability in IBM Filenet Content Manager 5.5.2/5.5.3
IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into a log file that could be accessed by an administrator on the local machine.
local
low complexity
ibm CWE-532
2.1
2019-10-10 CVE-2019-4265 Insecure Storage of Sensitive Information vulnerability in IBM Maximo Anywhere
IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker gaining sensitive information about the device.
local
low complexity
ibm CWE-922
2.1
2019-09-30 CVE-2019-4112 Improper Privilege Management vulnerability in IBM Websphere Extreme Scale
IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-269
3.3
2019-09-17 CVE-2019-4171 Missing Encryption of Sensitive Data vulnerability in IBM Cognos Controller
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or session cookies.
network
high complexity
ibm CWE-311
3.7