Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-07-01 CVE-2019-4410 Cross-site Scripting vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2019-07-01 CVE-2019-4386 Exposed Dangerous Method or Function vulnerability in IBM DB2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash.
network
low complexity
ibm CWE-749
6.5
2019-07-01 CVE-2019-4383 Unspecified vulnerability in IBM Spectrum Protect Plus 10.1.1/10.1.2/10.1.3
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle or MongoDB databases, a redirected restore operation may result in an escalation of user privileges.
local
low complexity
ibm
6.7
2019-07-01 CVE-2019-4357 Unspecified vulnerability in IBM Spectrum Protect Plus 10.1.1/10.1.2/10.1.3
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirected restore operation specifying a target path may allow execution of arbitrary code on the system.
local
low complexity
ibm
6.7
2019-07-01 CVE-2019-4337 Missing Authentication for Critical Function vulnerability in IBM Robotic Process Automation With Automation Anywhere 11.0.0.0/11.0.0.1/11.0.0.2
IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes.
network
low complexity
ibm CWE-306
5.3
2019-07-01 CVE-2019-4299 Information Exposure Through Log Files vulnerability in IBM Robotic Process Automation With Automation Anywhere
IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled.
local
low complexity
ibm CWE-532
5.5
2019-07-01 CVE-2019-4297 LDAP Injection vulnerability in IBM Robotic Process Automation With Automation Anywhere
IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection.
network
low complexity
ibm CWE-90
5.4
2019-07-01 CVE-2019-4295 Unspecified vulnerability in IBM Robotic Process Automation With Automation Anywhere
IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker with specialized access to obtain highly sensitive from the credential vault.
network
low complexity
ibm
4.9
2019-07-01 CVE-2019-4237 Cross-site Scripting vulnerability in IBM products
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page.
network
low complexity
ibm CWE-79
5.4
2019-07-01 CVE-2019-4102 Inadequate Encryption Strength vulnerability in IBM DB2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
high complexity
ibm CWE-326
5.9