CVE-2023-30444 – IBM Watson Machine Learning on Cloud Pak for Data server-side request forgery
https://notcve.org/view.php?id=CVE-2023-30444
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350. • https://www.ibm.com/support/pages/node/6985859 • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2022-36769 – IBM Cloud Pak for Data file upload
https://notcve.org/view.php?id=CVE-2022-36769
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034. • https://exchange.xforce.ibmcloud.com/vulnerabilities/232034 https://www.ibm.com/support/pages/node/6980959 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2022-41731 – IBM Watson Knowledge Catalog on Cloud Pak SQL injection
https://notcve.org/view.php?id=CVE-2022-41731
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 237402. • https://exchange.xforce.ibmcloud.com/vulnerabilities/237402 https://www.ibm.com/support/pages/node/6890729 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-41297 – IBM Db2U cross-site request forgery
https://notcve.org/view.php?id=CVE-2022-41297
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212. IBM Db2U 3.5, 4.0 y 4.5 es vulnerable a Cross-Site Request Forgery (CSRF), lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas por un usuario en el que confía el sitio web. ID de IBM X-Force: 237212. • https://exchange.xforce.ibmcloud.com/vulnerabilities/237212 https://www.ibm.com/support/pages/node/6843071 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-22353
https://notcve.org/view.php?id=CVE-2022-22353
IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate permissions to obtain sensitive information by bypassing data masking rules using a CREATE TABLE SELECT statement. IBM X-Force ID: 220480. IBM Big SQL en IBM Cloud Pak for Data versiones 7.1.0, 7.1.1, 7.2.0 y 7.2.3, podría permitir a un usuario autenticado con los permisos adecuados obtener información confidencial al omitir las reglas de enmascaramiento de datos mediante una sentencia CREATE TABLE SELECT. IBM X-Force ID: 220480 • https://exchange.xforce.ibmcloud.com/vulnerabilities/220480 https://www.ibm.com/support/pages/node/6563021 •