Ibm Cloud Pak For Security vulnerabilities
55 known vulnerabilities affecting ibm/cloud_pak_for_security.
Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM40LOW2
Vulnerabilities
Page 3 of 3
CVE-2024-22337P4MEDIUMCVSS 5.5≥ 1.10.0.0, ≤ 1.10.11.02024-02-17
CVE-2024-22337 [MEDIUM] CWE-532 CVE-2024-22337: IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279977.
nvd
CVE-2024-22335P4MEDIUMCVSS 5.5≥ 1.10.0.0, ≤ 1.10.11.02024-02-17
CVE-2024-22335 [MEDIUM] CWE-532 CVE-2024-22335: IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279975.
nvd
CVE-2022-36776P4MEDIUMCVSS 5.4≥ 1.10.0.0, ≤ 1.10.2.0v1.10.0.0, 1.10.2.02022-11-11
CVE-2022-36776 [MEDIUM] CWE-79 CVE-2022-36776: IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. Thi
IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233663.
nvd
CVE-2024-25024P4MEDIUMCVSS 5.5≥ 1.10.0.0, ≤ 1.10.11.02024-08-15
CVE-2024-25024 [MEDIUM] CWE-312 CVE-2024-25024: IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 throug
IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 281430.
nvd
CVE-2021-29697P4MEDIUMCVSS 4.9v1.5.0.0v1.5.0.1+5 more2021-08-02
CVE-2021-29697 [MEDIUM] CVE-2021-29697: IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could all
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to obtain sensitive information through HTTP requests that could be used in further attacks against the system.
nvd
CVE-2021-39011P4MEDIUMCVSS 4.9≥ 1.10.0.0, ≤ 1.10.6.0≥ 1.10.0.0, < 1.10.6.02023-01-20
CVE-2021-39011 [MEDIUM] CWE-532 CVE-2021-39011: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive informatio
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645.
nvd
CVE-2020-4626P4MEDIUMCVSS 4.3v1.3.0.12020-11-30
CVE-2020-4626 [MEDIUM] CVE-2020-4626: IBM Cloud Pak for Security 1.3.0.1 (CP4S) could reveal sensitive information about the internal netw
IBM Cloud Pak for Security 1.3.0.1 (CP4S) could reveal sensitive information about the internal network to an authenticated user using a specially crafted HTTP request. IBM X-Force ID: 185362.
nvd
CVE-2023-47727P4MEDIUMCVSS 4.3≥ 1.10.0.0, ≤ 1.10.11.02024-05-02
CVE-2023-47727 [MEDIUM] CWE-1287 CVE-2023-47727: IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 throug
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could allow an authenticated user to modify dashboard parameters due to improper input validation. IBM X-Force ID: 272089.
nvd
CVE-2020-4967P4MEDIUMCVSS 4.3v1.3.0.12021-01-27
CVE-2020-4967 [MEDIUM] CWE-200 CVE-2020-4967: IBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers
IBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers which could be used in further attacks against the system. IBM X-Force ID: 192425.
nvd
CVE-2020-4696P4MEDIUMCVSS 4.3v1.3.0.12020-11-30
CVE-2020-4696 [MEDIUM] CWE-613 CVE-2020-4696: IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow
IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session. IBM X-Force ID: 186789.
nvd
CVE-2023-50951P4MEDIUMCVSS 4.3≥ 1.10.0.0, ≤ 1.10.11.02024-02-17
CVE-2023-50951 [MEDIUM] CWE-532 CVE-2023-50951: IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.
nvd
CVE-2022-38382P4MEDIUMCVSS 4.1≥ 1.10.0.0, ≤ 1.10.11.02024-08-13
CVE-2022-38382 [MEDIUM] CWE-613 CVE-2022-38382: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672.
nvd
CVE-2025-1334P4MEDIUMCVSS 4.0≥ 1.10.0.0, ≤ 1.10.11.02025-06-03
CVE-2025-1334 [MEDIUM] CWE-525 CVE-2025-1334: IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.
nvd
CVE-2020-4811P4LOWCVSS 2.4v1.4.0.0v1.5.0.0+3 more2021-05-14
CVE-2020-4811 [LOW] CWE-20 CVE-2020-4811: IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a priv
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a privileged user to inject inject malicious data using a specially crafted HTTP request due to improper input validation.
nvd
CVE-2022-38383P4LOWCVSS 3.3≥ 1.10.0.0, ≤ 1.10.11.02024-06-28
CVE-2022-38383 [LOW] CWE-525 CVE-2022-38383: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.
nvd
← Previous3 / 3