Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-09-30 CVE-2019-4304 Session Fixation vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation.
network
low complexity
ibm CWE-384
6.3
2019-09-30 CVE-2019-4280 Cleartext Transmission of Sensitive Information vulnerability in IBM Sterling File Gateway
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the system.
network
low complexity
ibm CWE-319
5.3
2019-09-30 CVE-2019-4115 Cross-site Scripting vulnerability in IBM Websphere Extreme Scale
IBM WebSphere eXtreme Scale 8.6 Admin API is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2019-09-30 CVE-2019-4109 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Websphere Extreme Scale
IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
6.1
2019-09-30 CVE-2019-4106 Cross-site Scripting vulnerability in IBM Websphere Extreme Scale
IBM WebSphere eXtreme Scale 8.6 Admin Console is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
4.8
2019-09-27 CVE-2019-4141 Memory Leak vulnerability in IBM Websphere MQ and Websphere MQ Appliance
IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.1 - 9.1.2 is vulnerable to a denial of service attack caused by a memory leak in the clustering code.
network
low complexity
ibm CWE-401
6.5
2019-09-26 CVE-2019-4378 Unspecified vulnerability in IBM MQ
IBM MQ 7.5.0.0 - 7.5.0.9, 7.1.0.0 - 7.1.0.9, 8.0.0.0 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 command server is vulnerable to a denial of service attack caused by an authenticated and authorized user using specially crafted PCF messages.
network
low complexity
ibm
4.0
2019-09-26 CVE-2019-4262 Server-Side Request Forgery (SSRF) vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF).
network
low complexity
ibm CWE-918
5.0
2019-09-25 CVE-2019-4571 Cross-site Scripting vulnerability in IBM Content Navigator 3.0.0
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2019-09-24 CVE-2019-4566 Cleartext Storage of Sensitive Information vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-312
5.5