CVE-2022-38391
- EPSS 0.03%
- Veröffentlicht 20.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:16:23
IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 233982.
CVE-2019-4137
- EPSS 0.19%
- Veröffentlicht 29.05.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:43:13
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred...
CVE-2019-4138
- EPSS 0.29%
- Veröffentlicht 29.05.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:43:13
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obta...
CVE-2019-4071
- EPSS 1.73%
- Veröffentlicht 09.05.2019 15:29:04
- Zuletzt bearbeitet 21.11.2024 04:43:07
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 157063.
CVE-2019-4072
- EPSS 0.23%
- Veröffentlicht 09.05.2019 15:29:04
- Zuletzt bearbeitet 21.11.2024 04:43:07
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the application back button users can remain logged in a...
CVE-2016-8943
- EPSS 0.23%
- Veröffentlicht 01.02.2017 20:59:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with...
CVE-2016-8941
- EPSS 0.15%
- Veröffentlicht 01.02.2017 20:59:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVE-2016-8942
- EPSS 0.13%
- Veröffentlicht 01.02.2017 20:59:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.
CVE-2016-5947
- EPSS 0.16%
- Veröffentlicht 26.09.2016 04:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
CVE-2016-5946
- EPSS 0.28%
- Veröffentlicht 26.09.2016 04:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.