Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-12 CVE-2024-40690 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-07-10 CVE-2023-33859 Response Discrepancy Information Exposure vulnerability in IBM Security Qradar EDR 3.12
IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy.
network
low complexity
ibm CWE-204
5.3
2024-07-10 CVE-2023-33860 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in IBM Security Qradar EDR 3.12
IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-614
5.3
2024-07-10 CVE-2023-35006 Cross-site Scripting vulnerability in IBM Security Qradar EDR 3.12
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection.
network
low complexity
ibm CWE-79
5.4
2024-07-10 CVE-2024-25023 Cleartext Storage of Sensitive Information vulnerability in IBM Cloud PAK for Security and Qradar Suite
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user.
local
low complexity
ibm CWE-312
5.5
2024-07-08 CVE-2024-31897 Server-Side Request Forgery (SSRF) vulnerability in IBM Cloud PAK for Business Automation
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
4.3
2024-07-08 CVE-2024-37528 Cross-site Scripting vulnerability in IBM Cloud PAK for Business Automation
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-07-08 CVE-2024-39723 Improper Authentication vulnerability in IBM Storage Virtualize 8.6
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator.
low complexity
ibm CWE-287
4.6
2024-06-30 CVE-2023-50964 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-06-30 CVE-2024-28794 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4