Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-04-28 CVE-2022-22441 Unspecified vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege escalation vulnerability.
network
low complexity
ibm
6.5
2022-04-27 CVE-2021-29776 Unspecified vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's dashboard providing the dashboard ID of that user.
network
low complexity
ibm
4.0
2022-04-27 CVE-2021-34587 Out-of-bounds Write vulnerability in multiple products
In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash.
network
low complexity
ibm bender CWE-787
5.0
2022-04-27 CVE-2021-38874 Unspecified vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations.
network
low complexity
ibm
4.0
2022-04-27 CVE-2021-38919 Unspecified vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users.
network
low complexity
ibm
5.0
2022-04-27 CVE-2021-38939 Information Exposure Through Log Files vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains.
network
low complexity
ibm CWE-532
5.0
2022-04-27 CVE-2022-22312 Out-of-bounds Write vulnerability in IBM Security Verify Password Synchronization
IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in.
network
low complexity
ibm CWE-787
4.0
2022-04-27 CVE-2022-22323 Out-of-bounds Write vulnerability in IBM Security Verify Password Synchronization
IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in.
network
low complexity
ibm CWE-787
4.0
2022-04-25 CVE-2021-39040 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Planning Analytics Workspace 2.0
IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes.
network
ibm CWE-434
6.0
2022-04-25 CVE-2022-22392 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Planning Analytics Workspace 2.0
IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution.
network
ibm CWE-434
6.8