StoredIQ
IBM · 8 CVEs
IBM StoredIQ 7.6.0.17 through 7.6.0.20 could disclose sensitive information to a local user due to data in certain dire…
Feb 3, 2020
IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u…
Aug 20, 2019
IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow a remote attacker to cause a denial of service attack using repeated…
Jul 31, 2019
IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow an authenticated user to obtain sensitive information that a privileg…
Jul 31, 2019
IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadin…
Apr 30, 2019
IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privile…
Nov 30, 2018
IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and una…
Nov 30, 2018
IBM StoredIQ 7.6 could allow an authenticated attacker to bypass certain security restrictions. By sending a specially-…
May 22, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-4224 | IBM StoredIQ 7.6.0.17 through 7.6.0.20 could disclose sensitive information to a local user due to data in certain directories not being encrypted when it cont… | MEDIUM | 0.19% | Feb 3, 2020 |
| CVE-2019-4167 | IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a u… | MEDIUM | 0.49% | Aug 20, 2019 |
| CVE-2019-4165 | IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow a remote attacker to cause a denial of service attack using repeated requests to the server. IBM X-Force ID:… | HIGH | 2.17% | Jul 31, 2019 |
| CVE-2019-4163 | IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow an authenticated user to obtain sensitive information that a privileged user should only be allowed to view.… | MEDIUM | 0.99% | Jul 31, 2019 |
| CVE-2019-4166 | IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted… | MEDIUM | 1.45% | Apr 30, 2019 |
| CVE-2018-1928 | IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpo… | MEDIUM | 0.32% | Nov 30, 2018 |
| CVE-2018-1927 | IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a use… | HIGH | 0.65% | Nov 30, 2018 |
| CVE-2018-1583 | IBM StoredIQ 7.6 could allow an authenticated attacker to bypass certain security restrictions. By sending a specially-crafted request, an authenticated attack… | MEDIUM | 0.79% | May 22, 2018 |
Showing 1 to 8 of 8 CVEs