Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In February 2024
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 260577.
CVSS Score
6.5
EPSS Score
0.0
Published
2024-02-02
IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236441.
CVSS Score
4.8
EPSS Score
0.001
Published
2024-02-02
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 260575.
CVSS Score
8.1
EPSS Score
0.001
Published
2024-02-02
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.
CVSS Score
9.8
EPSS Score
0.007
Published
2024-02-02
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.
CVSS Score
8.1
EPSS Score
0.903
Published
2024-02-02
IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146.
CVSS Score
9.8
EPSS Score
0.922
Published
2024-02-02
IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906.
CVSS Score
2.6
EPSS Score
0.0
Published
2024-02-02
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
CVSS Score
8.8
EPSS Score
0.212
Published
2024-02-02
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.
CVSS Score
8.8
EPSS Score
0.039
Published
2024-02-02
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-02-02


Contact Us

Shodan ® - All rights reserved