Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-02-17 CVE-2023-22868 Cross-site Scripting vulnerability in IBM Aspera Faspex 4.4.1
IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-02-17 CVE-2023-24964 Cleartext Storage of Sensitive Information vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files.
local
low complexity
ibm CWE-312
5.5
2023-02-12 CVE-2022-42444 Classic Buffer Overflow vulnerability in IBM APP Connect Enterprise
IBM App Connect Enterprise 11.0.0.8 through 11.0.0.19 and 12.0.1.0 through 12.0.5.0 is vulnerable to a buffer overflow.
network
low complexity
ibm CWE-120
6.5
2023-02-12 CVE-2022-43869 Use of Externally-Controlled Format String vulnerability in IBM Elastic Storage System and Spectrum Scale
IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack.
network
low complexity
ibm CWE-134
6.5
2023-02-08 CVE-2022-34362 Cross-site Scripting vulnerability in IBM Sterling Secure Proxy 6.0.3
IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.
network
low complexity
ibm CWE-79
4.6
2023-02-08 CVE-2022-35720 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM products
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a local attacker to decrypt sensitive information.
local
low complexity
ibm CWE-327
5.5
2023-02-08 CVE-2023-23475 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
4.6
2023-02-06 CVE-2022-42439 Information Exposure Through Log Files vulnerability in IBM products
IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party system’s credentials to be exposed to a privileged attacker.
network
low complexity
ibm CWE-532
4.9
2023-02-01 CVE-2022-43922 Inadequate Encryption Strength vulnerability in IBM APP Connect Enterprise Certified Container
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive information to an attacker due to a weak hash of an API Key in the configuration.
network
low complexity
ibm CWE-326
6.5
2023-02-01 CVE-2022-47983 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4