Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Cloud Pak System
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20479 1 Ibm 1 Cloud Pak System 2022-05-16 5.0 MEDIUM 7.5 HIGH
IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197498.
CVE-2020-4912 1 Ibm 1 Cloud Pak System 2021-07-21 6.5 MEDIUM 7.2 HIGH
IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user. IBM X-Force ID: 191287.
CVE-2020-4917 1 Ibm 1 Cloud Pak System 2021-01-05 6.8 MEDIUM 8.8 HIGH
IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191391.
CVE-2019-4130 1 Ibm 1 Cloud Pak System 2019-12-09 6.5 MEDIUM 8.8 HIGH
IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 158280.