IBM / Pureapplication System
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-4241 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authentication and obtain administrative acces… | HIGH | 7.8 | Jun 26, 2019 |
| CVE-2019-4235 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, which makes it easier for attackers to… | HIGH | 7.5 | Jun 26, 2019 |
| CVE-2019-4234 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. An attacker by intercepting the subsequ… | MEDIUM | 4.3 | Jun 26, 2019 |
| CVE-2019-4225 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 15… | MEDIUM | 4.4 | Jun 26, 2019 |
| CVE-2019-4224 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could a… | HIGH | 8.8 | Jun 26, 2019 |
| CVE-2015-0235 | glibc: __nss_hostname_digits_dots() heap-based buffer overflow | HIGH | 10.0 | Jan 28, 2015 |
| CVE-2014-6158 | Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4 iFix 10, 1.1 before 1.1.0.5, and 2.0 b… | HIGH | 9.0 | Jan 10, 2015 |
| CVE-2014-7169 KEV | bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271) | CRITICAL | 9.8 | Sep 25, 2014 |
| CVE-2014-6271 KEV | bash: specially-crafted environment variables can be used to inject shell commands | CRITICAL | 9.8 | Sep 24, 2014 |
| CVE-2014-0960 | IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intended access restrictions by esta… | MEDIUM | 6.6 | Jun 14, 2014 |
Showing 1 to 10 of 10 CVEs