Security Bulletin: IBM InfoSphere Information Server is affected by an information disclosure vulnerability in Kubernetes (CVE-2021-25740)

## Summary An information disclosure vulnerability in Kubernetes used by IBM InfoSphere Information Server was addressed. ## Vulnerability Details ** CVEID: **[CVE-2021-25740]() ** DESCRIPTION: **Kube ...

Continue Reading

CVSS3 - LOW

CVSS2 - LOW

Security Bulletin: B2B API of IBM Sterling B2B Integrator vulnerable to multiple issues due to CKEditor

## Summary IBM Sterling B2B Integrator has addressed the CKEditor security vulnerabilities in B2B API. ## Vulnerability Details ** CVEID: **[CVE-2021-32808]() ** DESCRIPTION: **CKEditor is vulnerable ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Bulletin: B2B API of IBM Sterling B2B Integrator vulnerable to security bypass due to OWASP ESAPI (CVE-2013-5960)

## Summary IBM Sterling B2B Integrator has addressed the vulnerability in OWASP ESAPI in B2B API ## Vulnerability Details ** CVEID: **[CVE-2013-5960]() ** DESCRIPTION: **OWASP ESAPI could allow a remo ...

Continue Reading

CVSS2 - MEDIUM

Apiman has potential permissions bypass

### Impact Incorrect default permissions for certain read-only resources in the Apiman 1.5.7.Final through 2.2.3.Final in the Apiman Manager REST API allows a remote authenticated attacker to access i ...

Continue Reading

CVSS3 - MEDIUM

Apiman has potential permissions bypass

### Impact Incorrect default permissions for certain read-only resources in the Apiman 1.5.7.Final through 2.2.3.Final in the Apiman Manager REST API allows a remote authenticated attacker to access i ...

Continue Reading

CVSS3 - MEDIUM

CVE-2022-39041

aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify an ...

Continue Reading

CVSS3 - CRITICAL

CVE-2022-39042

aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system ...

Continue Reading

CVSS3 - CRITICAL

CVE-2022-43438

The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the intended access rest ...

Continue Reading

CVSS3 - HIGH

Back to Main

Subscribe for the latest news: