Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-02-21 CVE-2023-25928 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-02-17 CVE-2022-43579 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-02-17 CVE-2022-36775 Injection vulnerability in IBM products
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.
network
low complexity
ibm CWE-74
6.5
2023-02-17 CVE-2023-22868 Cross-site Scripting vulnerability in IBM Aspera Faspex 4.4.1
IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-02-17 CVE-2023-24964 Cleartext Storage of Sensitive Information vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files.
local
low complexity
ibm CWE-312
5.5
2023-02-12 CVE-2022-42444 Classic Buffer Overflow vulnerability in IBM APP Connect Enterprise
IBM App Connect Enterprise 11.0.0.8 through 11.0.0.19 and 12.0.1.0 through 12.0.5.0 is vulnerable to a buffer overflow.
network
low complexity
ibm CWE-120
6.5
2023-02-12 CVE-2022-43869 Use of Externally-Controlled Format String vulnerability in IBM Elastic Storage System and Spectrum Scale
IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack.
network
low complexity
ibm CWE-134
6.5
2023-02-08 CVE-2022-34362 Cross-site Scripting vulnerability in IBM Sterling Secure Proxy 6.0.3
IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.
network
low complexity
ibm CWE-79
4.6
2023-02-08 CVE-2022-35720 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM products
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a local attacker to decrypt sensitive information.
local
low complexity
ibm CWE-327
5.5
2023-02-08 CVE-2023-23475 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
4.6