Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-06-03 CVE-2020-4307 Unspecified vulnerability in IBM Security Guardium 11.1
IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a denial of service attack.
low complexity
ibm
6.5
2020-06-03 CVE-2020-4190 Use of Hard-coded Credentials vulnerability in IBM Security Guardium 10.6/11.0/11.1
IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
local
low complexity
ibm CWE-798
6.7
2020-06-03 CVE-2020-4187 Unspecified vulnerability in IBM Security Guardium 11.1
IBM Security Guardium 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system.
network
low complexity
ibm
5.3
2020-06-03 CVE-2020-4182 Cross-site Scripting vulnerability in IBM Security Guardium 11.1
IBM Security Guardium 11.1 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2020-06-02 CVE-2020-4503 Cross-site Scripting vulnerability in IBM Planning Analytics Local
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2020-06-02 CVE-2020-4431 Cross-site Scripting vulnerability in IBM Planning Analytics Local
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-06-02 CVE-2020-4366 Cross-site Scripting vulnerability in IBM Planning Analytics Local
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2020-06-02 CVE-2020-4360 Cross-site Scripting vulnerability in IBM Planning Analytics Local
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-05-29 CVE-2020-4490 Unspecified vulnerability in IBM products
IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw.
network
low complexity
ibm
6.1
2020-05-29 CVE-2020-4306 Cross-site Scripting vulnerability in IBM Planning Analytics Local
IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4