Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-12-23 CVE-2020-4642 Unspecified vulnerability in IBM DB2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of service inside the "DB2 Management Service".
local
low complexity
ibm
5.5
2020-12-21 CVE-2020-4843 Cleartext Storage of Sensitive Information vulnerability in IBM Security Secret Server 10.6
IBM Security Secret Server 10.6 stores potentially sensitive information in config files that could be read by an authenticated user.
network
low complexity
ibm CWE-312
4.3
2020-12-21 CVE-2020-4842 Information Exposure Through an Error Message vulnerability in IBM Security Secret Server 10.6
IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
4.9
2020-12-21 CVE-2020-4841 Missing Authorization vulnerability in IBM Security Secret Server 10.6
IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-862
5.9
2020-12-21 CVE-2020-4840 Open Redirect vulnerability in IBM Security Secret Server 10.6
IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.1
2020-12-21 CVE-2020-4794 Incorrect Authorization vulnerability in IBM products
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking.
network
low complexity
ibm CWE-863
5.4
2020-12-21 CVE-2020-4757 Cross-site Scripting vulnerability in IBM Content Navigator 3.0.0
IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
6.4
2020-12-21 CVE-2020-4555 Session Fixation vulnerability in IBM Financial Transaction Manager
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
network
low complexity
ibm CWE-384
5.4
2020-12-18 CVE-2020-4764 Cross-Site Request Forgery (CSRF) vulnerability in IBM Planning Analytics 2.0
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
6.5
2020-12-17 CVE-2020-4845 Cross-site Scripting vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Key Lifecycle Manager 3.0.1 and 4.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4