CVE-2019-4234
- EPSS 0.17%
- Published 26.06.2019 15:15:10
- Last modified 21.11.2024 04:43:21
IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. An attacker by intercepting the subsequent requests can bypass business logic to modify the pattern to unlocked state. IBM X-Force...
CVE-2019-4235
- EPSS 0.27%
- Published 26.06.2019 15:15:10
- Last modified 21.11.2024 04:43:21
IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 159417.
CVE-2019-4241
- EPSS 0.05%
- Published 26.06.2019 15:15:10
- Last modified 21.11.2024 04:43:22
IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authentication and obtain administrative access. IBM X-Force ID: 159467.
CVE-2019-4224
- EPSS 0.31%
- Published 26.06.2019 15:15:09
- Last modified 21.11.2024 04:43:20
IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM ...
CVE-2019-4225
- EPSS 0.04%
- Published 26.06.2019 15:15:09
- Last modified 21.11.2024 04:43:20
IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 159242.
- EPSS 85.45%
- Published 28.01.2015 19:59:00
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 fu...
- EPSS 2.36%
- Published 10.01.2015 02:59:26
- Last modified 12.04.2025 10:46:40
Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4 iFix 10, 1.1 before 1.1.0.5, and 2.0 before 2.0.0.1 and Workload Deployer 3.1.0.7 before IF5 allow remote authenticated users to ...
- EPSS 90.11%
- Published 25.09.2014 01:55:04
- Last modified 12.04.2025 10:46:40
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...
- EPSS 94.22%
- Published 24.09.2014 18:48:04
- Last modified 12.04.2025 10:46:40
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
CVE-2014-0960
- EPSS 0.13%
- Published 14.06.2014 11:18:54
- Last modified 12.04.2025 10:46:40
IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intended access restrictions by establishing an SSH session from a deployed virtual machine.