Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-04-10 CVE-2020-4362 Improper Privilege Management vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector.
network
low complexity
ibm CWE-269
6.5
2020-04-08 CVE-2020-4291 Session Fixation vulnerability in IBM Security Information Queue
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI.
network
ibm CWE-384
4.3
2020-04-08 CVE-2020-4290 Authentication Bypass by Spoofing vulnerability in IBM Security Information Queue
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access.
network
low complexity
ibm CWE-290
5.5
2020-04-08 CVE-2020-4289 Information Exposure vulnerability in IBM Security Information Queue
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag.
network
low complexity
ibm CWE-200
5.0
2020-04-08 CVE-2020-4284 Information Exposure vulnerability in IBM Security Information Queue
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI.
network
low complexity
ibm CWE-200
5.0
2020-04-08 CVE-2020-4282 Improper Authentication vulnerability in IBM Security Information Queue
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow an authenticated user to perform unauthorized actions by bypassing illegal character restrictions.
network
low complexity
ibm CWE-287
4.0
2020-04-08 CVE-2020-4164 Information Exposure vulnerability in IBM Security Information Queue
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could expose sensitive information from applicatino errors which could be used in further attacks against the system.
network
low complexity
ibm CWE-200
4.0
2020-04-08 CVE-2019-4603 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Rational Quality Manager 6.0.2/6.0.6/6.0.6.1
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to create keywords through the REST API and have them appear as if they were created by another user.
network
low complexity
ibm CWE-732
4.0
2020-04-08 CVE-2019-4601 Information Exposure Through an Error Message vulnerability in IBM Rational Quality Manager 6.0.2/6.0.6/6.0.6.1
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to obtain sensitive information from a stack trace that could aid in further attacks against the system.
network
low complexity
ibm CWE-209
4.0
2020-04-03 CVE-2020-4273 Improper Privilege Management vulnerability in IBM Spectrum Scale
IBM Spectrum Scale 4.2 and 5.0 could allow a local unprivileged attacker with intimate knowledge of the enviornment to execute commands as root using specially crafted input.
local
ibm CWE-269
6.9