CVE-2024-52897 – IBM MQ Appliance information disclosure
https://notcve.org/view.php?id=CVE-2024-52897
IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. • https://www.ibm.com/support/pages/node/7178086 • CWE-209: Generation of Error Message Containing Sensitive Information •
CVE-2024-52896 – IBM MQ Appliance information disclosure
https://notcve.org/view.php?id=CVE-2024-52896
IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. • https://www.ibm.com/support/pages/node/7178244 • CWE-209: Generation of Error Message Containing Sensitive Information •
CVE-2024-4230
https://notcve.org/view.php?id=CVE-2024-4230
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. • https://jvn.jp/vu/JVNVU92857077/index.html https://www.edgecross.org/client_info/EDGECROSS/view/userweb/ext/en/data-download/pdf/ECD-TE10-0003-01-EN.pdf • CWE-73: External Control of File Name or Path •
CVE-2024-4229
https://notcve.org/view.php?id=CVE-2024-4229
Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than a folder that only users with administrative privilege have permission to modify. • https://jvn.jp/vu/JVNVU92857077/index.html https://www.edgecross.org/client_info/EDGECROSS/view/userweb/ext/en/data-download/pdf/ECD-TE10-0003-01-EN.pdf • CWE-276: Incorrect Default Permissions •
CVE-2022-33954 – IBM Robotic Process Automation information disclosure
https://notcve.org/view.php?id=CVE-2022-33954
IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials. IBM Robotic Process Automation 21.0.1, 21.0.2 y 21.0.3 podrían permitir que un usuario con acceso físico al sistema obtenga información confidencial debido a credenciales insuficientemente protegidas. • https://www.ibm.com/support/pages/node/6608458 • CWE-522: Insufficiently Protected Credentials •