CVE-2021-20565
- EPSS 0.16%
- Veröffentlicht 14.05.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:47
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protectio...
CVE-2021-20577
- EPSS 0.17%
- Veröffentlicht 10.05.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:48
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ...
CVE-2021-20538
- EPSS 0.13%
- Veröffentlicht 10.05.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:44
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919.
CVE-2020-4967
- EPSS 0.16%
- Veröffentlicht 27.01.2021 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:29
IBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers which could be used in further attacks against the system. IBM X-Force ID: 192425.
CVE-2020-4820
- EPSS 0.19%
- Veröffentlicht 27.01.2021 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:17
IBM Cloud Pak for Security (CP4S) 1.4.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w...
CVE-2020-4816
- EPSS 0.26%
- Veröffentlicht 27.01.2021 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:17
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive informa...
CVE-2020-4815
- EPSS 0.13%
- Veröffentlicht 27.01.2021 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:16
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote user to obtain sensitive information from HTTP response headers that could be used in further attacks against the system.
CVE-2020-4628
- EPSS 0.18%
- Veröffentlicht 27.01.2021 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:00
IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the syst...
CVE-2020-4696
- EPSS 0.11%
- Veröffentlicht 30.11.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:08
IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session. IBM X-Force ID: 186789.
- EPSS 1.04%
- Veröffentlicht 30.11.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:00
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.