CVE-2021-29802
- EPSS 0.1%
- Published 23.08.2021 16:15:08
- Last modified 21.11.2024 06:01:50
IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CVE-2021-29704
- EPSS 0.09%
- Published 23.08.2021 16:15:07
- Last modified 21.11.2024 06:01:40
IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2021-29780
- EPSS 0.19%
- Published 19.07.2021 16:15:08
- Last modified 21.11.2024 06:01:47
IBM Resilient OnPrem v41.1 of IBM Security SOAR could allow an authenticated user to perform actions that they should not have access to due to improper input validation. IBM X-Force ID: 203085.
CVE-2021-20566
- EPSS 0.09%
- Published 16.06.2021 17:15:07
- Last modified 21.11.2024 05:46:47
IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 199238.
CVE-2021-20567
- EPSS 0.01%
- Published 16.06.2021 17:15:07
- Last modified 21.11.2024 05:46:47
IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.
- EPSS 2.63%
- Published 11.12.2020 15:15:12
- Last modified 21.11.2024 05:33:01
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
CVE-2020-4864
- EPSS 0.08%
- Published 29.10.2020 16:15:15
- Last modified 21.11.2024 05:33:20
IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP address. IBM X-Force ID: 190567.
CVE-2020-4636
- EPSS 0.67%
- Published 16.10.2020 17:15:13
- Last modified 21.11.2024 05:33:01
IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.
CVE-2019-4533
- EPSS 0.19%
- Published 28.08.2020 15:15:12
- Last modified 21.11.2024 04:43:41
IBM Resilient SOAR V38.0 users may experience a denial of service of the SOAR Platform due to a insufficient input validation. IBM X-Force ID: 165589.
CVE-2019-4579
- EPSS 0.13%
- Published 28.08.2020 15:15:12
- Last modified 21.11.2024 04:43:45
IBM Resilient SOAR 38 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 167236.