Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-04-08 CVE-2019-4051 Information Exposure vulnerability in IBM API Connect
Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like the machine id, system uuid, filesystem paths, network interface names along with their mac addresses.
network
low complexity
ibm CWE-200
5.0
2019-04-08 CVE-2019-4045 Unspecified vulnerability in IBM products
IBM Business Automation Workflow and IBM Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 provide embedded document management features.
network
low complexity
ibm
4.0
2019-04-08 CVE-2018-2000 Cross-Site Request Forgery (CSRF) vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
ibm CWE-352
6.8
2019-04-08 CVE-2018-1999 Information Exposure vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system.
network
low complexity
ibm CWE-200
4.0
2019-04-08 CVE-2018-1997 Unspecified vulnerability in IBM products
IBM Business Automation Workflow and Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 are vulnerable to a denial of service attack.
network
low complexity
ibm
4.0
2019-04-08 CVE-2018-1885 Information Exposure vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request.
network
low complexity
ibm CWE-200
5.0
2019-04-08 CVE-2018-1853 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Spectrum Protect Backup-Archive Client
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim.
network
ibm CWE-1021
4.3
2019-04-02 CVE-2019-4080 Resource Exhaustion vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing.
network
low complexity
ibm CWE-400
6.5
2019-04-02 CVE-2018-1917 Information Exposure vulnerability in IBM products
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information.
network
low complexity
ibm CWE-200
4.0
2019-04-02 CVE-2018-1906 Unspecified vulnerability in IBM products
IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a specially crafted HTTP request.
network
low complexity
ibm
4.0