Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2022-03-01 CVE-2021-38955 Unspecified vulnerability in IBM AIX and Vios
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands.
local
low complexity
ibm
2.1
2022-03-01 CVE-2020-4925 Unspecified vulnerability in IBM Spectrum Scale 5.0.0/5.1.0
A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requests and preventing the daemon to service other requests.
local
low complexity
ibm
2.1
2022-02-25 CVE-2021-38993 Unspecified vulnerability in IBM AIX and Vios
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the smbcd daemon to cause a denial of service.
local
low complexity
ibm
2.1
2022-02-24 CVE-2021-39038 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim.
network
ibm CWE-1021
3.5
2022-02-24 CVE-2021-38995 Unspecified vulnerability in IBM AIX and Vios
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service.
local
low complexity
ibm
2.1
2022-02-24 CVE-2021-38994 Unspecified vulnerability in IBM AIX and Vios
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service.
local
low complexity
ibm
2.1
2022-02-23 CVE-2022-22333 Classic Buffer Overflow vulnerability in IBM products
IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted.
low complexity
ibm CWE-120
3.3
2022-02-16 CVE-2019-4352 Unspecified vulnerability in IBM Maximo Anywhere 7.6.4.0
IBM Maximo Anywhere 7.6.4.0 applications could allow obfuscation of the application source code.
local
low complexity
ibm
2.1
2022-02-16 CVE-2019-4351 Unspecified vulnerability in IBM Maximo Anywhere 7.6.4.0
IBM Maximo Anywhere 7.6.4.0 applications could disclose sensitive information to a user with physical access to the device.
local
low complexity
ibm
2.1
2022-02-14 CVE-2021-39079 Cross-site Scripting vulnerability in IBM Cognos Analytics Mobile
IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5