CVE-2023-26276 – IBM QRadar information disclosure
https://notcve.org/view.php?id=CVE-2023-26276
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147. • https://exchange.xforce.ibmcloud.com/vulnerabilities/248147 https://www.ibm.com/support/pages/node/7006081 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2023-26273 – IBM QRadar security bypass
https://notcve.org/view.php?id=CVE-2023-26273
IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134. • https://exchange.xforce.ibmcloud.com/vulnerabilities/248134 https://www.ibm.com/support/pages/node/7006083 • CWE-20: Improper Input Validation •
CVE-2023-32339 – IBM Business Automation Workflow cross-site scripting
https://notcve.org/view.php?id=CVE-2023-32339
IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 255587. • https://https://www.ibm.com/support/pages/node/6998727 https://https://www.ibm.com/support/pages/node/7001291 https://www.ibm.com/support/pages/node/6998727 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-33842 – IBM SPSS Modeler information disclosure
https://notcve.org/view.php?id=CVE-2023-33842
IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server SSL key which could allow a local user to decrypt and obtain sensitive information. IBM X-Force ID: 256117. • https://exchange.xforce.ibmcloud.com/vulnerabilities/256117 https://https://www.ibm.com/support/pages/node/7004299 •
CVE-2023-28956 – IBM Spectrum Protect Backup-Archive Client privilege escalation
https://notcve.org/view.php?id=CVE-2023-28956
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. IBM X-Force ID: 251767. IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. • https://exchange.xforce.ibmcloud.com/vulnerabilities/251767 https://www.ibm.com/support/pages/node/7005519 • CWE-266: Incorrect Privilege Assignment •