
CVE-2022-31769
https://notcve.org/view.php?id=CVE-2022-31769
10 Jun 2022 — IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreSQL, which could be used in further attacks against the system. IBM X-Force ID: 228219. IBM Spectrum Copy Data Management versiones 2.2.0.0 hasta 2.2.15.0, podría permitir a un atacante remoto visualizar la información de configuración del producto almacenada en PostgreSQL, que podría usarse en otros ataques contra el sistema. IBM X-Force ID: 228219 • https://exchange.xforce.ibmcloud.com/vulnerabilities/228219 •

CVE-2022-30611
https://notcve.org/view.php?id=CVE-2022-30611
10 Jun 2022 — IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using some fields of the form in the portal UI to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/227364 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-30610
https://notcve.org/view.php?id=CVE-2022-30610
10 Jun 2022 — IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL could then rewrite the original page with a phishing page. IBM X-Force ID: 227363. IBM Spectrum Copy Data Management versiones 2.2.0.0 hasta 2.2.15.0, es vulnerable a un tabnabbing inve... • https://exchange.xforce.ibmcloud.com/vulnerabilities/227363 • CWE-269: Improper Privilege Management •

CVE-2022-22479
https://notcve.org/view.php?id=CVE-2022-22479
10 Jun 2022 — IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887. IBM Spectrum Copy Data Management versiones 2.2.0.0 hasta 2.2.15.0, es vulnerable a un ataque de tipo cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas desde un usuario en el que el sitio... • https://exchange.xforce.ibmcloud.com/vulnerabilities/225887 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2022-22426
https://notcve.org/view.php?id=CVE-2022-22426
10 Jun 2022 — IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication restrictions, caused by the lack of proper session management. An attacker could exploit this vulnerability to bypass authentication and gain unauthorized access to the Spectrum Copy Data Management catalog which contains metadata. IBM X-Force ID: 223718. IBM Spectrum Copy Data Management Admin versiones 2.2.0.0 hasta 2.2.15.0, podría permitir a un atacante local omitir las restricciones de... • https://exchange.xforce.ibmcloud.com/vulnerabilities/223718 •

CVE-2021-3669 – kernel: reading /proc/sysvipc/shm does not scale with large shared memory segment counts
https://notcve.org/view.php?id=CVE-2021-3669
11 May 2022 — A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. Se ha encontrado un fallo en el kernel de Linux. La medición del uso de la memoria compartida no escala con grandes recuentos de segmentos de memoria compartida, lo que podría conllevar a el agotamiento de recursos y el DoS. Red Hat Advanced Cluster Management for Kubernetes 2.5.0 images Red Hat Advanced Cluster Management for Kube... • https://access.redhat.com/security/cve/CVE-2021-3669 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2022-22354
https://notcve.org/view.php?id=CVE-2022-22354
14 Mar 2022 — IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485. IBM Spectrum Protect Plus versiones 10.1.0.0 hasta 10.1.9.2 e IBM Spectrum Copy Data Management versiones 2.2.0.0 hasta 2.2.14.3, no limitan la duración de una conexión, lo que podría permitir un a... • https://exchange.xforce.ibmcloud.com/vulnerabilities/220485 •

CVE-2022-22344
https://notcve.org/view.php?id=CVE-2022-22344
14 Mar 2022 — IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 220038 IBM Spectrum Copy Data Management versiones 2.2.0.0 hasta 2.2.14.3, es vulnerable a una inyección de encabezados HTTP, causada por una comprobación inapropiada de la entrada... • https://exchange.xforce.ibmcloud.com/vulnerabilities/220038 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2021-39055
https://notcve.org/view.php?id=CVE-2021-39055
14 Mar 2022 — IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214534. IBM Spectrum Copy Data Management versiones 2.2.0.0 hasta 2.2.14.3, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitr... • https://exchange.xforce.ibmcloud.com/vulnerabilities/214534 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-39051
https://notcve.org/view.php?id=CVE-2021-39051
14 Mar 2022 — IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the application server registration form in the portal UI to enumerate and attack services that are running on those hosts. IBM X-Force ID: 214441. IBM Spectrum Copy Data Management versiones 2.2.0.0 hasta 2.2.14.3, es vulnerable a un ataque de... • https://exchange.xforce.ibmcloud.com/vulnerabilities/214441 • CWE-918: Server-Side Request Forgery (SSRF) •