Medium · CVSS 6.1
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182717.
Published Aug 10, 2020 · Updated Sep 17, 2024
Medium · CVSS 5.3
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 174402.
Published Aug 27, 2020 · Updated Sep 17, 2024
Medium · CVSS 5.1
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to cause interruption of the service operations. IBM X-Force ID: 185372.
Published Aug 4, 2020 · Updated Sep 17, 2024
Low · CVSS 2.8
A buffer length validation vulnerability in Asylo versions prior to 0.6.0 allows an attacker to read data they should not have access to. The 'enc_untrusted_recvfrom' function generates a return value which is deserialized by 'MessageReader', and copied into three different 'extents'. The length of the third 'extents' is controlled by the outside world, and not verified on copy, allowing the attacker to force Asylo to copy trusted memory data into an untrusted buffer of significantly small length.. We recommend updating Asylo to version 0.6.0 or later.
Published Aug 12, 2020 · Updated Sep 17, 2024
Low · CVSS 2.9
IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted container pool. IBM X-Force ID: 184746.
Published Aug 28, 2020 · Updated Sep 17, 2024
Critical · CVSS 9.4
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
Published Aug 2, 2022 · Updated Sep 16, 2024
High · CVSS 8.4
IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caused by improper bounds checking. A local attacker could manipulate CD UNIX to obtain root provileges. IBM X-Force ID: 184578.
Published Aug 24, 2020 · Updated Sep 16, 2024
High · CVSS 7.1
The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host.
Published Aug 24, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.7
RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.
Published Aug 31, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.7
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.
Published Aug 10, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.4
An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the ecall_restore function fails to validate the range of the output_len pointer, an attacker can manipulate the tmp_output_len value and write to an arbitrary location in the trusted (enclave) memory. We recommend updating Asylo to version 0.6.0 or later.
Published Aug 12, 2020 · Updated Sep 16, 2024
High · CVSS 7.3
The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
Published Aug 2, 2022 · Updated Sep 16, 2024
High · CVSS 8.8
hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy files referenced in the update process, and a remote attacker could induce a user to crafted web page, causing damage such as malicious code infection.
Published Aug 7, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.2
IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device with invalid arguments. IBM X-Force ID: 181992.
Published Aug 31, 2020 · Updated Sep 16, 2024
High · CVSS 7.8
IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183317.
Published Aug 3, 2020 · Updated Sep 16, 2024
Medium · CVSS 4.3
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to send a specially crafted HTTP GET request to read attachments on the server that they should not have access to. IBM X-Force ID: 179539.
Published Aug 4, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.3
Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer overflow vulnerability in the Likewise component. A remote unauthenticated malicious attacker may potentially exploit this vulnerability to cause a process restart.
Published Aug 27, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.
Published Aug 17, 2020 · Updated Sep 16, 2024
High · CVSS 7.2
This affects all versions of package s3-kilatstorage.
Published Aug 2, 2022 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174401.
Published Aug 24, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.3
IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 177839.
Published Aug 3, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.5
IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an attacker in bypassing security mechanisms in future attacks. IBM X-Force ID: 181860.
Published Aug 11, 2020 · Updated Sep 16, 2024
High · CVSS 7.8
IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183321.
Published Aug 3, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.2
IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deployment or upgrade pertaining to xcat services. IBM X-Force ID: 179163.
Published Aug 24, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.5
A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified by other users without authorization to do so. IBM X-Force ID: 186019.
Published Aug 19, 2020 · Updated Sep 16, 2024
Medium · CVSS 4.4
IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184747.
Published Aug 24, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages between the CCDM and the host computer, allowing an attacker with physical access to internal ATM components to commit deposit forgery by intercepting and modifying messages to the host computer, such as the amount and value of currency being deposited.
Published Aug 21, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
Published Aug 18, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.4
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the authenticated user. Affected versions of Communication Manager are 7.0.x, 7.1.x prior to 7.1.3.5 and 8.0.x. Affected versions of Messaging are 7.0.x, 7.1 and 7.1 SP1.
Published Aug 11, 2020 · Updated Sep 16, 2024
High · CVSS 7.8
IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183319.
Published Aug 3, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.6
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.
Published Aug 6, 2020 · Updated Sep 16, 2024
High · CVSS 8
Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and allows for the creation of Python objects. Through this flaw in the ROS core package of actionlib, an attacker with local or remote access can make the ROS Master, execute arbitrary code in Python form. Consider yaml.safe_load() instead. Located first in actionlib/tools/library.py:132. See links for more info on the bug.
Published Aug 20, 2020 · Updated Sep 16, 2024
Low · CVSS 3.3
IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 184880.
Published Aug 27, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.
Published Aug 18, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.5
An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an unhandled exception, resulting in a crash. Fixed in 2.20.1-0ubuntu2.24, 2.20.9-0ubuntu7.16, 2.20.11-0ubuntu27.6.
Published Aug 6, 2020 · Updated Sep 16, 2024
Medium · CVSS 4.3
IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters that could be stored in the IBM Content Navigator database. IBM X-Force ID: 183316.
Published Aug 20, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.
Published Aug 17, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 187194.
Published Aug 17, 2021 · Updated Sep 16, 2024
Medium · CVSS 5.9
IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 181395.
Published Aug 4, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.5
IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 186233.
Published Aug 14, 2020 · Updated Sep 16, 2024
High · CVSS 7.5
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
Published Aug 10, 2020 · Updated Sep 16, 2024
High · CVSS 8.1
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.
Published Aug 13, 2020 · Updated Sep 16, 2024
High · CVSS 8.2
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 179156.
Published Aug 3, 2020 · Updated Sep 16, 2024
High · CVSS 7.5
Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource consumption, which may allow an attacker to cause a denial-of-service condition.
Published Aug 25, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.4
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
Published Aug 2, 2022 · Updated Sep 16, 2024
High · CVSS 7.1
This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing advertisement attribution fraud. Mintegral can remotely activate hooks on the UIApplication, openURL, SKStoreProductViewController, loadProductWithParameters and NSURLProtocol methods along with anti-debug and proxy detection protection. If those hooks are active MintegralAdSDK sends obfuscated data about every opened URL in an application to their servers. Note that the malicious functionality is enabled even if the SDK was not enabled to serve ads.
Published Aug 24, 2020 · Updated Sep 16, 2024
Medium · CVSS 4.7
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
Published Aug 27, 2020 · Updated Sep 16, 2024
High · CVSS 8.1
This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.
Published Aug 21, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root.
Published Aug 25, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 183046.
Published Aug 4, 2020 · Updated Sep 16, 2024