Author: Angelo Barbosa

CVE-2024-25027 | IBM Security Verify Access Docker 10.0.6 Snapshot missing encryption (XFDB-281607)

A vulnerability, which was classified as problematic, was found in IBM Security Verify Access Docker 10.0.6. This affects an unknown part of the component Snapshot Handler. The manipulation leads to missing encryption of sensitive data. This vulnerability is uniquely identified as CVE-2024-25027. It is possible to launch the attack on the local host. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-50959 | IBM Cloud Pak for Business Automation up to 23.0.2 unknown vulnerability (XFDB-275938)

A vulnerability, which was classified as problematic, has been found in IBM Cloud Pak for Business Automation. Affected by this issue is some unknown functionality. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere. This vulnerability is handled as CVE-2023-50959. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-50311 | IBM CICS Transaction Gateway for Multiplatforms 9.2/9.3 insufficiently protected credentials (XFDB-273612)

A vulnerability classified as problematic was found in IBM CICS Transaction Gateway for Multiplatforms 9.2/9.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to insufficiently protected credentials. This vulnerability is known as CVE-2023-50311. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-22353 | IBM WebSphere Application Server Liberty up to 24.0.0.3 Request resource consumption (XFDB-280400)

A vulnerability classified as problematic has been found in IBM WebSphere Application Server Liberty up to 24.0.0.3. Affected is an unknown function of the component Request Handler. The manipulation leads to resource consumption. This vulnerability is traded as CVE-2024-22353. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More