4 results (0.008 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704. • https://exchange.xforce.ibmcloud.com/vulnerabilities/251704 https://www.ibm.com/support/pages/node/7009747 • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782. • https://exchange.xforce.ibmcloud.com/vulnerabilities/251782 https://www.ibm.com/support/pages/node/7009747 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 237402. • https://exchange.xforce.ibmcloud.com/vulnerabilities/237402 https://www.ibm.com/support/pages/node/6890729 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.2EPSS: 0%CPEs: 2EXPL: 0

IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force ID: 159229. IBM InfoSphere Information Server versión 11.7.1.0 almacena una clave de encriptación con codificación común que se podría usar para descifrar información confidencial. ID de IBM X-Force: 159229. • https://exchange.xforce.ibmcloud.com/vulnerabilities/159229 https://www.ibm.com/support/docview.wss?uid=ibm10881197 • CWE-798: Use of Hard-coded Credentials •