İçeriğe atla
Noroxi

IBM kayıtları

ibm üreticisine ait 8.833 yayımlanmış kayıt.

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

8.833 kayıt
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · struts10 Mar 2017

  • IBM Aspera Faspex code execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    ibm · aspera faspex17 Şub 2023

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allo

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    ibm · sterling b2b integrator2 Oca 2016

  • IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %86

    ibm · planning analytics18 Ara 2019

  • IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when config

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %70

    ibm · data risk manager7 May 2020

  • IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %62

    ibm · data risk manager7 May 2020

  • CVE-2001-0797
    68Bu hafta

    Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe

    KritikCVSS 10,0SilahlaştırılmışEPSS %95

    sgi · irix12 Ara 2001

  • CVE-2015-0235
    68Bu hafta

    Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen

    KritikCVSS 10,0SilahlaştırılmışEPSS %95

    gnu · glibc28 Oca 2015

  • CVE-2010-0425
    68Bu hafta

    modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, w

    KritikCVSS 10,0SilahlaştırılmışEPSS %94

    apache · http server5 Mar 2010

  • CVE-2020-4430
    68Bu hafta

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.

    OrtaCVSS 4,3KEVSilahlaştırılmışEPSS %69

    ibm · data risk manager7 May 2020

  • CVE-2019-4279
    63Bu hafta

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted

    KritikCVSS 9,8SilahlaştırılmışEPSS %80

    ibm · websphere application server17 May 2019

  • CVE-2007-4880
    63Bu hafta

    Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2

    KritikCVSS 10,0SilahlaştırılmışEPSS %76

    ibm · tivoli storage manager client27 Eyl 2007

  • CVE-2024-22319
    62Bu hafta

    IBM Operational Decision Manager JDNI injection

    KritikCVSS 9,8Kavram kanıtıEPSS %76

    ibm · operational decision manager1 Şub 2024

  • CVE-2017-1092
    62Bu hafta

    IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows serv

    KritikCVSS 9,8SilahlaştırılmışEPSS %76

    ibm · informix open admin tool22 May 2017

  • CVE-2020-4429
    61Bu hafta

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.

    KritikCVSS 9,8SilahlaştırılmışEPSS %72

    ibm · data risk manager7 May 2020

  • CVE-2008-4828
    61Bu hafta

    Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 thr

    KritikCVSS 10,0SilahlaştırılmışEPSS %71

    ibm · tivoli storage manager client5 May 2009

  • CVE-2020-4211
    60Bu hafta

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.

    KritikCVSS 9,8İstismar yokEPSS %71

    ibm · spectrum protect24 Şub 2020

  • CVE-2003-0694
    60Bu hafta

    The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using

    KritikCVSS 10,0SilahlaştırılmışEPSS %66

    sendmail · advanced message server6 Eki 2003

  • CVE-2008-2240
    59Planlayın

    Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to

    KritikCVSS 10,0SilahlaştırılmışEPSS %65

    ibm · lotus domino22 May 2008

  • CVE-2009-3699
    59Planlayın

    Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1

    KritikCVSS 10,0SilahlaştırılmışEPSS %62

    ibm · vios15 Eki 2009

  • CVE-2007-1675
    58Planlayın

    Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.

    KritikCVSS 10,0Kavram kanıtıEPSS %61

    ibm · lotus domino28 Mar 2007

  • CVE-2007-1868
    58Planlayın

    The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-da

    KritikCVSS 10,0SilahlaştırılmışEPSS %59

    ibm · tivoli provisioning manager os deployment4 Nis 2007

  • CVE-2020-4280
    57Planlayın

    IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of

    YüksekCVSS 8,8İstismar yokEPSS %73

    ibm · qradar security information and event manager8 Eki 2020