CVE-2024-31898
- EPSS 0.03%
- Published 30.06.2024 18:15:03
- Last modified 21.11.2024 09:14:06
IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM X-Force ID: 288182.
CVE-2023-50952
- EPSS 0.06%
- Published 30.06.2024 18:15:02
- Last modified 21.11.2024 08:37:35
IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attac...
CVE-2023-50953
- EPSS 0.06%
- Published 30.06.2024 18:15:02
- Last modified 21.11.2024 08:37:36
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. IBM X-Force ID: 275775.
CVE-2024-35119
- EPSS 0.07%
- Published 30.06.2024 17:15:03
- Last modified 21.11.2024 09:19:48
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-F...
CVE-2023-50954
- EPSS 0.11%
- Published 30.06.2024 17:15:02
- Last modified 21.11.2024 08:37:36
IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.
CVE-2024-28798
- EPSS 0.29%
- Published 30.06.2024 17:15:02
- Last modified 21.11.2024 09:06:56
IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu...
CVE-2024-31902
- EPSS 0.14%
- Published 30.06.2024 17:15:02
- Last modified 21.11.2024 09:14:06
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 289234.
CVE-2023-35022
- EPSS 0.01%
- Published 30.06.2024 16:15:02
- Last modified 21.11.2024 08:07:50
IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorization to access. IBM X-Force ID: 258254.
CVE-2024-28795
- EPSS 0.11%
- Published 30.06.2024 16:15:02
- Last modified 21.11.2024 09:06:56
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with...
CVE-2024-22352
- EPSS 0.07%
- Published 21.03.2024 02:52:02
- Last modified 21.11.2024 08:56:06
IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 280361.