CVE-2023-27877 – IBM Planning Analytics Cartridge for Cloud Pak for Data information disclosure
https://notcve.org/view.php?id=CVE-2023-27877
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905. • https://exchange.xforce.ibmcloud.com/vulnerabilities/247905 https://www.ibm.com/support/pages/node/6999351 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-287: Improper Authentication •
CVE-2023-28955 – IBM Watson Knowledge Catalog denial of service
https://notcve.org/view.php?id=CVE-2023-28955
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704. • https://exchange.xforce.ibmcloud.com/vulnerabilities/251704 https://www.ibm.com/support/pages/node/7009747 • CWE-20: Improper Input Validation •
CVE-2023-28958 – IBM Watson Knowledge Catalog CSV injection
https://notcve.org/view.php?id=CVE-2023-28958
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782. • https://exchange.xforce.ibmcloud.com/vulnerabilities/251782 https://www.ibm.com/support/pages/node/7009747 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •
CVE-2023-27540 – IBM Watson CP4D Data Stores denial of service
https://notcve.org/view.php?id=CVE-2023-27540
IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924. • https://exchange.xforce.ibmcloud.com/vulnerabilities/248924 https://www.ibm.com/support/pages/node/7009883 • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2023-28953 – IBM Cognos Analytics on Cloud Pak for Data improper access control
https://notcve.org/view.php?id=CVE-2023-28953
IBM Cognos Analytics on Cloud Pak for Data 4.0 could allow an attacker to make system calls that might compromise the security of the containers due to misconfigured security context. IBM X-Force ID: 251465. • https://exchange.xforce.ibmcloud.com/vulnerabilities/251465 https://security.netapp.com/advisory/ntap-20230814-0001 https://www.ibm.com/support/pages/node/7006413 •