CVE-2025-14754
- EPSS 0.65%
- Veröffentlicht 18.09.2026 15:20:53
- Zuletzt bearbeitet 22.09.2026 12:50:05
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
CVE-2025-14753
- EPSS 0.62%
- Veröffentlicht 18.09.2026 15:20:23
- Zuletzt bearbeitet 22.09.2026 15:17:08
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
CVE-2025-0165
- EPSS 0.38%
- Veröffentlicht 30.08.2025 12:47:56
- Zuletzt bearbeitet 18.12.2025 17:50:12
IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or ...
CVE-2024-49790
- EPSS 0.18%
- Veröffentlicht 28.08.2025 14:15:43
- Zuletzt bearbeitet 26.09.2026 21:10:00
IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t...
CVE-2025-0719
- EPSS 0.32%
- Veröffentlicht 26.02.2025 14:15:11
- Zuletzt bearbeitet 08.08.2025 19:35:40
IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le...
CVE-2023-27545
- EPSS 0.2%
- Veröffentlicht 29.02.2024 02:15:08
- Zuletzt bearbeitet 01.04.2025 16:46:33
IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 248947.
CVE-2023-26023
- EPSS 0.66%
- Veröffentlicht 19.07.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:50:36
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
CVE-2023-26026
- EPSS 0.57%
- Veröffentlicht 19.07.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:50:37
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
CVE-2023-27877
- EPSS 0.54%
- Veröffentlicht 19.07.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:53:37
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
CVE-2023-27540
- EPSS 1.3%
- Veröffentlicht 10.07.2023 16:15:49
- Zuletzt bearbeitet 21.11.2024 07:53:07
IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.