Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-01-04 CVE-2020-4912 Improper Privilege Management vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user.
network
low complexity
ibm CWE-269
6.5
2020-12-21 CVE-2020-4843 Cleartext Storage of Sensitive Information vulnerability in IBM Security Secret Server 10.6
IBM Security Secret Server 10.6 stores potentially sensitive information in config files that could be read by an authenticated user.
network
low complexity
ibm CWE-312
4.0
2020-12-21 CVE-2020-4842 Information Exposure Through an Error Message vulnerability in IBM Security Secret Server 10.6
IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
4.0
2020-12-21 CVE-2020-4841 Information Exposure vulnerability in IBM Security Secret Server 10.6
IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
ibm CWE-200
4.3
2020-12-21 CVE-2020-4840 Open Redirect vulnerability in IBM Security Secret Server 10.6
IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
ibm CWE-601
5.8
2020-12-21 CVE-2020-4794 Incorrect Authorization vulnerability in IBM products
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking.
network
low complexity
ibm CWE-863
5.5
2020-12-21 CVE-2020-4757 Cross-site Scripting vulnerability in IBM Content Navigator 3.0.0
IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
6.4
2020-12-21 CVE-2020-4555 Session Fixation vulnerability in IBM Financial Transaction Manager
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
network
low complexity
ibm CWE-384
5.5
2020-12-18 CVE-2020-4764 Cross-Site Request Forgery (CSRF) vulnerability in IBM Planning Analytics 2.0
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
ibm CWE-352
4.3
2020-12-17 CVE-2020-4846 Information Exposure Through an Error Message vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
4.0