CVE-2023-26278 – IBM QRadar WinCollect Agent privilege escalation
https://notcve.org/view.php?id=CVE-2023-26278
IBM QRadar WinCollect Agent 10.0 through 10.1.3 could allow a local authenticated attacker to gain elevated privileges on the system. IBM X-Force ID: 248158. • https://exchange.xforce.ibmcloud.com/vulnerabilities/248158 https://www.ibm.com/support/pages/node/6999341 •
CVE-2023-26277 – IBM QRadar WinCollect Agent privilege escalation
https://notcve.org/view.php?id=CVE-2023-26277
IBM QRadar WinCollect Agent 10.0 though 10.1.3 could allow a local user to execute commands on the system due to execution with unnecessary privileges. IBM X-Force ID: 248156. • https://https://exchange.xforce.ibmcloud.com/vulnerabilities/248156 https://www.ibm.com/support/pages/node/6999343 •
CVE-2023-32342 – IBM GSKit information disclosure
https://notcve.org/view.php?id=CVE-2023-32342
IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 255828. • https://exchange.xforce.ibmcloud.com/vulnerabilities/255828 • CWE-203: Observable Discrepancy •
CVE-2023-30440 – IBM PowerVM Hypervisor denial of service
https://notcve.org/view.php?id=CVE-2023-30440
IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through FW1030.10 could allow a local attacker with control a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer partition or arbitrary data corruption. IBM X-Force ID: 253175. • https://exchange.xforce.ibmcloud.com/vulnerabilities/253175 https://www.ibm.com/support/pages/node/6997133 • CWE-20: Improper Input Validation •
CVE-2023-32336 – IBM InfoSphere Information Server code execution
https://notcve.org/view.php?id=CVE-2023-32336
IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285. • https://exchange.xforce.ibmcloud.com/vulnerabilities/255285 https://www.ibm.com/support/pages/node/6995879 • CWE-502: Deserialization of Untrusted Data •