cbcvebase.

Ibm Cloud Pak For Security vulnerabilities

55 known vulnerabilities affecting ibm/cloud_pak_for_security.

Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM40LOW2

Vulnerabilities

Page 1 of 3
CVE-2022-38387P3HIGHCVSS 8.8≥ 1.10.0.0, ≤ 1.10.2.0≥ 1.10.0.0, < 1.10.2.02022-11-11
CVE-2022-38387 [HIGH] CWE-78 CVE-2022-38387: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attac IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 233786.
nvd
CVE-2023-47726P3HIGHCVSS 8.8≥ 1.10.12.0, ≤ 1.10.21.02024-06-18
CVE-2023-47726 [HIGH] CWE-1287 CVE-2023-47726: IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 throu IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to execute certain arbitrary commands due to improper input validation. IBM X-Force ID: 272087.
nvd
CVE-2021-29696P3HIGHCVSS 7.2v1.5.0.0v1.5.0.1+5 more2021-08-02
CVE-2021-29696 [HIGH] CVE-2021-29696: IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could all IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
nvd
CVE-2025-25022P3HIGHCVSS 8.8≥ 1.10.0.0, ≤ 1.10.11.02025-06-03
CVE-2025-25022 [HIGH] CWE-260 CVE-2025-25022: IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.
nvd
CVE-2020-4627P3CRITICALCVSS 9.0v1.3.0.12020-11-30
CVE-2020-4627 [CRITICAL] CWE-1236 CVE-2020-4627: IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
nvd
CVE-2021-20578P3CRITICALCVSS 9.8v1.7.0.0v1.7.1.0+2 more2021-09-30
CVE-2021-20578 [CRITICAL] CWE-287 CVE-2021-20578: IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.
nvd
CVE-2021-20538P3CRITICALCVSS 9.1v1.5.0.0v1.5.0.12021-05-10
CVE-2021-20538 [CRITICAL] CWE-863 CVE-2021-20538: IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive informa IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919.
nvd
CVE-2022-38385P3HIGHCVSS 8.1≥ 1.10.0.0, ≤ 1.10.2.0≥ 1.10.0.0, < 1.10.2.02022-11-15
CVE-2022-38385 [HIGH] CWE-20 CVE-2022-38385: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to ob IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 233777.
nvd
CVE-2023-30993P3HIGHCVSS 7.5≥ 1.9.0.0, ≤ 1.9.2.02023-06-27
CVE-2023-30993 [HIGH] CWE-200 CVE-2023-30993: IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API k IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another tenant's account. IBM X-Force ID: 254136.
nvd
CVE-2024-28799P3HIGHCVSS 7.5≥ 1.10.0.0, ≤ 1.10.11.02024-08-14
CVE-2024-28799 [HIGH] CWE-214 CVE-2024-28799: IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 throug IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, in non default configurations, during back-end commands which may result in the unexpected disclosure of this information. IBM X-Force ID: 287173.
nvd
CVE-2025-25021P3HIGHCVSS 7.2≥ 1.10.0.0, ≤ 1.10.11.02025-06-03
CVE-2025-25021 [HIGH] CWE-94 CVE-2025-25021: IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code.
nvd
CVE-2023-47728P3HIGHCVSS 7.5≥ 1.10.0.0, ≤ 1.10.11.02024-08-16
CVE-2023-47728 [HIGH] CWE-209 CVE-2023-47728: IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 throug IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the request. This information could be used in further attacks against the system. IBM X-Force ID: 272201.
nvd
CVE-2021-29894P3HIGHCVSS 7.5v1.7.0.0v1.7.1.0+2 more2021-09-30
CVE-2021-29894 [HIGH] CWE-327 CVE-2021-29894: IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected c IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207320.
nvd
CVE-2022-36777P4MEDIUMCVSS 6.5≥ 1.10.0.0, ≤ 1.10.11.02023-11-22
CVE-2022-36777 [MEDIUM] CWE-200 CVE-2022-36777: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.16.0could allow an authenticated user to obtain sensitive version information that could aid in further attacks against the system. IBM X-Force ID: 233665.
nvd
CVE-2024-28782P4MEDIUMCVSS 6.5≥ 1.10.0.0, ≤ 1.10.11.02024-04-03
CVE-2024-28782 [MEDIUM] CWE-256 CVE-2024-28782: IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 throug IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 285698.
nvd
CVE-2021-39089P4MEDIUMCVSS 6.5≥ 1.10.0.0, ≤ 1.10.6.0≥ 1.10.0.0, < 1.10.6.02023-01-20
CVE-2021-39089 [MEDIUM] CWE-200 CVE-2021-39089: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obt IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 216387.
nvd
CVE-2025-25020P4MEDIUMCVSS 6.5≥ 1.10.0.0, ≤ 1.10.11.02025-06-03
CVE-2025-25020 [MEDIUM] CWE-1287 CVE-2025-25020: IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input.
nvd
CVE-2025-25019P4MEDIUMCVSS 6.5≥ 1.10.0.0, ≤ 1.10.11.02025-06-03
CVE-2025-25019 [MEDIUM] CWE-613 CVE-2025-25019: IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.
nvd
CVE-2021-39013P4MEDIUMCVSS 6.5v1.7.0.0v1.7.1.0+1 more2021-12-22
CVE-2021-39013 [MEDIUM] CWE-200 CVE-2021-39013: IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses that could be used in further attacks against the system. IBM X-Force ID: 213651.
nvd
CVE-2022-38386P4MEDIUMCVSS 5.9≥ 1.10.0.0, ≤ 1.10.11.02024-05-01
CVE-2022-38386 [MEDIUM] CWE-1275 CVE-2022-38386: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10. IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.
nvd
Ibm Cloud Pak For Security vulnerabilities | cvebase