CVE-2023-40694 – IBM Watson CP4D Data Stores information disclosure
https://notcve.org/view.php?id=CVE-2023-40694
IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 264838. IBM Watson CP4D Data Stores 4.0.0 a 4.8.4 almacena información potencialmente confidencial en archivos de registro que un usuario local podría leer. ID de IBM X-Force: 264838. • https://exchange.xforce.ibmcloud.com/vulnerabilities/264838 https://www.ibm.com/support/pages/node/7150286 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2023-27283 – IBM Aspera Orchestrator information disclosure
https://notcve.org/view.php?id=CVE-2023-27283
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545. IBM Aspera Orchestrator 4.0.1 podría permitir a un atacante remoto enumerar nombres de usuarios debido a discrepancias de respuesta observables. ID de IBM X-Force: 248545. • https://exchange.xforce.ibmcloud.com/vulnerabilities/248545 https://www.ibm.com/support/pages/node/7150191 • CWE-204: Observable Response Discrepancy •
CVE-2023-37407 – IBM Aspera Orchestrator command execution
https://notcve.org/view.php?id=CVE-2023-37407
IBM Aspera Orchestrator 4.0.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 260116. IBM Aspera Orchestrator 4.0.1 podría permitir que un atacante remoto autenticado ejecute comandos arbitrarios en el sistema enviando una solicitud especialmente manipulada. ID de IBM X-Force: 260116. • https://exchange.xforce.ibmcloud.com/vulnerabilities/260116 https://www.ibm.com/support/pages/node/7150117 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2023-47727 – IBM QRadar Suite Software file manipulation
https://notcve.org/view.php?id=CVE-2023-47727
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could allow an authenticated user to modify dashboard parameters due to improper input validation. IBM X-Force ID: 272089. IBM Cloud Pak for Security 1.10.0.0 a 1.10.11.0 e IBM QRadar Suite Software 1.10.12.0 a 1.10.20.0 podrían permitir a un usuario autenticado modificar los parámetros del panel debido a una validación de entrada incorrecta. ID de IBM X-Force: 272089. • https://exchange.xforce.ibmcloud.com/vulnerabilities/272089 https://www.ibm.com/support/pages/node/7149968 • CWE-1287: Improper Validation of Specified Type of Input •
CVE-2024-28764 – IBM WebSphere Automation CSV injection
https://notcve.org/view.php?id=CVE-2024-28764
IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623. IBM WebSphere Automation 1.7.0 podría permitir que un atacante con acceso privilegiado a la red realice una inyección CSV. Un atacante podría ejecutar comandos arbitrarios en el sistema, causados por una validación inadecuada del contenido del archivo csv. • https://exchange.xforce.ibmcloud.com/vulnerabilities/285623 https://www.ibm.com/support/pages/node/7149857 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •