Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-09-29 CVE-2012-2160 Cross-site Scripting vulnerability in IBM Rational Change 5.3
IBM Rational Change 5.3 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-79
6.1
2022-09-29 CVE-2012-4818 Unspecified vulnerability in IBM Infosphere Information Server 8.1/8.5/8.7
IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories.
network
low complexity
ibm
6.5
2022-09-29 CVE-2015-1931 Cleartext Storage of Sensitive Information vulnerability in multiple products
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
local
low complexity
ibm suse redhat CWE-312
5.5
2022-09-28 CVE-2022-22387 Cross-site Scripting vulnerability in IBM Application Gateway 1.0
IBM Application Gateway is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2022-09-28 CVE-2022-35282 Server-Side Request Forgery (SSRF) vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF).
low complexity
ibm CWE-918
6.5
2022-09-28 CVE-2022-35722 Cross-site Scripting vulnerability in IBM Jazz for Service Management
IBM Jazz for Service Management is vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2022-09-28 CVE-2022-36771 Unspecified vulnerability in IBM Qradar User Behavior Analytics 1.0.0/4.1.0/4.1.1
IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to.
network
low complexity
ibm
6.5
2022-09-13 CVE-2022-22330 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Control Desk
IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag.
network
low complexity
ibm CWE-732
5.3
2022-09-13 CVE-2022-22483 Improper Privilege Management vulnerability in IBM DB2
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used.
network
low complexity
ibm CWE-269
6.5
2022-09-13 CVE-2022-35637 Unspecified vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement into the Db2expln tool.
network
low complexity
ibm
6.5