CVE-2022-38389
- EPSS 0.02%
- Published 03.02.2023 00:15:11
- Last modified 21.11.2024 07:16:22
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. ...
CVE-2022-22486
- EPSS 0.02%
- Published 03.02.2023 00:15:09
- Last modified 21.11.2024 06:46:53
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. ...
CVE-2021-20349
- EPSS 0.04%
- Published 09.08.2021 16:15:06
- Last modified 21.11.2024 05:46:26
IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 194599.
CVE-2019-4608
- EPSS 0.21%
- Published 10.03.2020 12:15:11
- Last modified 21.11.2024 04:43:50
IBM Tivoli Workload Scheduler 9.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a ...
CVE-2019-4031
- EPSS 0.11%
- Published 16.10.2019 13:15:11
- Last modified 21.11.2024 04:43:03
IBM Workload Scheduler Distributed 9.2, 9.3, 9.4, and 9.5 contains a vulnerability that could allow a local user to write files as root in the file system, which could allow the attacker to gain root privileges. IBM X-Force ID: 155997.
CVE-2018-1386
- EPSS 0.03%
- Published 14.03.2018 00:29:00
- Last modified 21.11.2024 03:59:43
IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could allow a local user to with special access to gain root privileges. IBM X-Force ID: 138208.
CVE-2017-1716
- EPSS 0.04%
- Published 13.12.2017 18:29:00
- Last modified 20.04.2025 01:37:25
IBM Tivoli Workload Scheduler 8.6.0, 9.1.0, and 9.2.0 could disclose sensitive information to a local attacker due to improper permission settings. IBM X-Force ID: 134638.