CVE-2021-38971
https://notcve.org/view.php?id=CVE-2021-38971
IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an authorized user to bypass data masking rules and obtain sensitve information. IBM X-Force ID: 212620. IBM Data Virtualization on Cloud Pak for Data versiones 1.3.0, 1.4.1, 1.5.0, 1.7.1 y 1.7.3, podría permitir a un usuario autorizado omitir las reglas de enmascaramiento de datos y obtener información confidencial. IBM X-Force ID: 212620 • https://exchange.xforce.ibmcloud.com/vulnerabilities/212620 https://www.ibm.com/support/pages/node/6551076 •
CVE-2021-38899
https://notcve.org/view.php?id=CVE-2021-38899
IBM Cloud Pak for Data 2.5 could allow a local user with special privileges to obtain highly sensitive information. IBM X-Force ID: 209575. IBM Cloud Pak for Data versión 2.5, podría permitir a un usuario local con privilegios especiales conseguir información altamente confidencial. ID de IBM X-Force: 209575 • https://exchange.xforce.ibmcloud.com/vulnerabilities/209575 https://www.ibm.com/support/pages/node/6490435 •
CVE-2021-20486
https://notcve.org/view.php?id=CVE-2021-20486
IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668. IBM Cloud Pak for Data versión 3.0, podría permitir a un usuario autenticado obtener información confidencial cuando es instalado con plugins adicionales. IBM X-Force ID: 197668 • https://exchange.xforce.ibmcloud.com/vulnerabilities/197668 https://www.ibm.com/support/pages/node/6456033 •
CVE-2019-4428
https://notcve.org/view.php?id=CVE-2019-4428
IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162807. IBM Watson Assistant para IBM Cloud Pak for Data versiones 1.0.0 hasta 1.3.0, es vulnerable a ataques de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando así la funcionalidad prevista conllevando potencialmente a una divulgación de credenciales dentro de una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/162807 https://www.ibm.com/support/pages/node/1125585 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •