Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-11-06 CVE-2020-4484 Unspecified vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive information to an authenticated user that could be used in further attacks against the system.
network
low complexity
ibm
4.3
2020-11-06 CVE-2020-4483 Information Exposure Through an Error Message vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
4.3
2020-11-06 CVE-2020-4482 Unspecified vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow an authenticated user to bypass security.
network
low complexity
ibm
6.5
2020-11-03 CVE-2020-4785 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM APP Connect Enterprise Certified Container
IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
5.4
2020-11-03 CVE-2020-4649 Information Exposure vulnerability in IBM Planning Analytics Local
IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions.
network
low complexity
ibm CWE-200
4.3
2020-10-29 CVE-2020-4864 Authentication Bypass by Spoofing vulnerability in IBM Resilient Security Orchestration Automation and Response 38.0
IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP address.
low complexity
ibm CWE-290
4.3
2020-10-29 CVE-2019-4563 Session Fixation vulnerability in IBM Security Directory Server 6.4.0.0
IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-384
5.3
2020-10-29 CVE-2019-4547 Information Exposure Through an Error Message vulnerability in IBM Security Directory Server 6.4.0.0
IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data.
network
low complexity
ibm CWE-209
5.3
2020-10-28 CVE-2020-4782 Path Traversal vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
6.5
2020-10-20 CVE-2020-4756 Improper Resource Shutdown or Release vulnerability in IBM Elastic Storage Server and Spectrum Scale
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service.
local
low complexity
ibm CWE-404
5.5