5 results (0.023 seconds)

CVSS: 4.4EPSS: 0%CPEs: 1EXPL: 0

IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user. • https://www.ibm.com/support/pages/node/7170411 • CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 8.8EPSS: 0%CPEs: 7EXPL: 0

IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210. • https://exchange.xforce.ibmcloud.com/vulnerabilities/238210 https://www.ibm.com/support/pages/node/6909427 • CWE-425: Direct Request ('Forced Browsing') •

CVSS: 8.1EPSS: 0%CPEs: 3EXPL: 0

IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 211048. IBM CloudPak for Multicloud Monitoring versiones 2.0 y 2.3, presenta algunos contenedores que son ejecutados en modo privilegiado, lo que es vulnerable a un filtrado de información del host o a una destrucción si el acceso no autorizado a estos contenedores pudiera ejecutar comandos arbitrarios. IBM X-Force ID: 211048 • https://exchange.xforce.ibmcloud.com/vulnerabilities/211048 https://www.ibm.com/support/pages/node/6599639 •

CVSS: 4.0EPSS: 0%CPEs: 1EXPL: 0

IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 188902. IBM Cloud Pak for Multicloud Management anterior a versión 2.3, permite a unas páginas web ser almacenadas localmente para que pueda ser leídas por otro usuario en el sistema. IBM X-Force ID: 188902 • https://exchange.xforce.ibmcloud.com/vulnerabilities/188902 https://www.ibm.com/support/pages/node/6454019 • CWE-922: Insecure Storage of Sensitive Information •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM Cloud Pak for Multicloud Management Monitoring 2.2 returns potentially sensitive information in headers which could lead to further attacks against the system. IBM X-Force ID: 194513. IBM Cloud Pak para Multicloud Management Monitoring versión 2.2, devuelve información potencialmente confidencial en encabezados que podrían conllevar a nuevos ataques contra el sistema. IBM X-Force ID: 194513 • https://exchange.xforce.ibmcloud.com/vulnerabilities/194513 https://www.ibm.com/support/pages/node/6426997 •