Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-03-15 CVE-2023-47147 External Control of File Name or Path vulnerability in IBM Sterling Secure Proxy 6.0.3/6.1.0
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions.
network
low complexity
ibm CWE-73
5.3
2024-03-15 CVE-2023-47699 Cross-site Scripting vulnerability in IBM Sterling Secure Proxy 6.0.3/6.1.0
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2024-03-15 CVE-2023-46179 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in IBM Sterling Secure Proxy 6.0.3/6.1.0
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-614
4.3
2024-03-15 CVE-2023-46182 Cross-site Scripting vulnerability in IBM Sterling Secure Proxy 6.0.3/6.1.0
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-03-15 CVE-2023-47162 Cross-site Scripting vulnerability in IBM Sterling Secure Proxy 6.0.3/6.1.0
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2024-03-14 CVE-2024-27265 Cross-Site Request Forgery (CSRF) vulnerability in IBM Integration BUS 10.1
IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
6.5
2024-03-01 CVE-2023-28525 Cross-site Scripting vulnerability in IBM products
IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
4.8
2024-03-01 CVE-2023-28949 Cross-Site Request Forgery (CSRF) vulnerability in IBM products
IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
6.5
2024-03-01 CVE-2023-50305 Weak Password Requirements vulnerability in IBM products
IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
local
high complexity
ibm CWE-521
5.1
2024-02-12 CVE-2022-22506 Unspecified vulnerability in IBM Robotic Process Automation 21.0.2
IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants.
low complexity
ibm
4.6