Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-06-24 CVE-2021-39047 Cross-site Scripting vulnerability in multiple products
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting.
network
low complexity
ibm netapp CWE-79
6.1
2022-06-21 CVE-2021-39006 Unspecified vulnerability in IBM Qradar Wincollect 10.0/10.0.1
IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices.
network
low complexity
ibm
5.0
2022-06-20 CVE-2022-22318 Insufficient Session Expiration vulnerability in IBM Curam Social Program Management 8.0.0/8.0.1
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
network
low complexity
ibm CWE-613
6.5
2022-06-20 CVE-2022-22414 Unspecified vulnerability in IBM Robotic Process Automation
IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory.
local
low complexity
ibm
5.5
2022-06-17 CVE-2022-30607 Information Exposure vulnerability in IBM Robotic Process Automation
IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive information due to information properly masked in the control center UI.
network
low complexity
ibm CWE-200
6.5
2022-06-10 CVE-2022-22479 Cross-Site Request Forgery (CSRF) vulnerability in IBM Spectrum Copy Data Management
IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
ibm CWE-352
6.8
2022-06-10 CVE-2022-31769 Unspecified vulnerability in IBM Spectrum Copy Data Management
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreSQL, which could be used in further attacks against the system.
network
low complexity
ibm
5.3
2022-06-07 CVE-2020-36530 SQL Injection vulnerability in IBM Sevone Network Performance Management
A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22.
network
ibm CWE-89
6.0
2022-06-07 CVE-2020-36531 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Sevone Network Performance Management
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22.
network
ibm CWE-1236
6.0
2022-06-06 CVE-2022-22396 Insufficiently Protected Credentials vulnerability in IBM Spectrum Protect Plus
Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases.
network
low complexity
ibm CWE-522
5.0