Skip to main content

Vendor/product archive

ibm / pureapplication_system CVEs

Beta · best-effort

8 CVEs tagged to ibm / pureapplication_system2 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2019-4241

Published Jun 26, 2019

IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authentication and obtain administrative access. IBM X-Force ID: 1…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4235

Published Jun 26, 2019

IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user acco…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4234

Published Jun 26, 2019

IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. An attacker by intercepting the subsequent requests can byp…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4225

Published Jun 26, 2019

IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 159242.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4224

Published Jun 26, 2019

IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0960

Published Jun 14, 2014

IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intended access restrictions by establishing an SSH sess…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1