CVE-2023-28955 – IBM Watson Knowledge Catalog denial of service
https://notcve.org/view.php?id=CVE-2023-28955
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704. • https://exchange.xforce.ibmcloud.com/vulnerabilities/251704 https://www.ibm.com/support/pages/node/7009747 • CWE-20: Improper Input Validation •
CVE-2022-41731 – IBM Watson Knowledge Catalog on Cloud Pak SQL injection
https://notcve.org/view.php?id=CVE-2022-41731
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 237402. • https://exchange.xforce.ibmcloud.com/vulnerabilities/237402 https://www.ibm.com/support/pages/node/6890729 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •