Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-10-20 CVE-2020-4755 Cross-site Scripting vulnerability in IBM Spectrum Scale
IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-10-20 CVE-2020-4749 Reliance on Cookies without Validation and Integrity Checking vulnerability in IBM Spectrum Scale
IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-565
4.3
2020-10-20 CVE-2020-4748 Cross-site Scripting vulnerability in IBM Spectrum Scale
IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2020-10-20 CVE-2020-4564 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-10-20 CVE-2020-4491 Unspecified vulnerability in IBM Spectrum Scale
IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial of service by sending a large number of RPC requests to the mmfsd daemon which would cause the service to crash.
local
low complexity
ibm
5.5
2020-10-15 CVE-2019-4552 Unspecified vulnerability in IBM Security Access Manager and Security Verify Access
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks.
network
low complexity
ibm
6.1
2020-10-14 CVE-2020-4395 Insufficient Session Expiration vulnerability in IBM Security Access Manager Appliance 9.0.7
IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
network
low complexity
ibm CWE-613
5.4
2020-10-12 CVE-2020-4741 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.5/11.7
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-10-12 CVE-2020-4740 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.5/11.7
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to HTML injection.
low complexity
ibm CWE-79
5.2
2020-10-12 CVE-2020-4689 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to CVS Injection.
network
low complexity
ibm CWE-1236
6.8