
CVE-2024-35145 – IBM Maximo Application Suite cross-site scripting
https://notcve.org/view.php?id=CVE-2024-35145
25 Jan 2025 — IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. • https://www.ibm.com/support/pages/node/7174956 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-35134 – IBM Analytics Content Hub information disclosure
https://notcve.org/view.php?id=CVE-2024-35134
25 Jan 2025 — IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. • https://www.ibm.com/support/pages/node/7172787 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2024-39750 – IBM Analytics Content Hub buffer overflow
https://notcve.org/view.php?id=CVE-2024-39750
25 Jan 2025 — IBM Analytics Content Hub 2.0 is vulnerable to a buffer overflow due to improper return length checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. • https://www.ibm.com/support/pages/node/7172787 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2023-38271 – IBM Cloud Pak System information disclosure
https://notcve.org/view.php?id=CVE-2023-38271
25 Jan 2025 — IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to obtain sensitive information from log files. IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to obtain sensitive information from log files. • https://www.ibm.com/support/pages/node/7159533 • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2023-38713 – IBM Cloud Pak System information disclosure
https://notcve.org/view.php?id=CVE-2023-38713
25 Jan 2025 — IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the system that could aid in further attacks against the system. IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the system that could aid in further attacks against the system. • https://www.ibm.com/support/pages/node/7159533 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2023-38714 – IBM Cloud Pak System information disclosure
https://notcve.org/view.php?id=CVE-2023-38714
25 Jan 2025 — IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the system that could aid in further attacks against the system. IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the system that could aid in further attacks against the system. • https://www.ibm.com/support/pages/node/7159533 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2023-38013 – IBM Cloud Pak System information disclosure
https://notcve.org/view.php?id=CVE-2023-38013
25 Jan 2025 — IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in HTTP responses that could aid in further attacks against the system. • https://www.ibm.com/support/pages/node/7159533 • CWE-201: Insertion of Sensitive Information Into Sent Data •

CVE-2023-38012 – IBM Cloud Pak System directory traversal
https://notcve.org/view.php?id=CVE-2023-38012
25 Jan 2025 — IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. • https://www.ibm.com/support/pages/node/7148474 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-38716 – IBM Cloud Pak System information disclosure
https://notcve.org/view.php?id=CVE-2023-38716
25 Jan 2025 — IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive information about the system that could aid in further attacks against the system. • https://www.ibm.com/support/pages/node/7148474 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2024-35114 – IBM Control Center information disclosure
https://notcve.org/view.php?id=CVE-2024-35114
25 Jan 2025 — IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts. • https://www.ibm.com/support/pages/node/7174842 • CWE-204: Observable Response Discrepancy •