Ibm Daeja Viewone vulnerabilities
10 known vulnerabilities affecting ibm/daeja_viewone.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM6LOW1
Vulnerabilities
Page 1 of 1
CVE-2019-4246MEDIUMCVSS 5.3≥ 5.0, ≤ 5.0.62019-10-01
CVE-2019-4246 [MEDIUM] CVE-2019-4246: IBM Daeja ViewONE Virtual 5.0 through 5.0.6 could expose internal parameters to ViewONE clients that
IBM Daeja ViewONE Virtual 5.0 through 5.0.6 could expose internal parameters to ViewONE clients that could be used in further attacks against the system. IBM X-Force ID: 159521.
nvd
CVE-2019-4456HIGHCVSS 7.1≥ 5.0, ≤ 5.0.6v5.0.5+1 more2019-07-30
CVE-2019-4456 [HIGH] CWE-611 CVE-2019-4456: IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External
IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 163620.
cvelistv5nvd
CVE-2019-4260MEDIUMCVSS 5.3≥ 5.0, ≤ 5.0.5v5.0+5 more2019-07-02
CVE-2019-4260 [MEDIUM] CVE-2019-4260: IBM Daeja ViewONE Professional, Standard & Virtual 5.0 through 5.0.5 could allow an unauthorized use
IBM Daeja ViewONE Professional, Standard & Virtual 5.0 through 5.0.5 could allow an unauthorized user to download server files resulting in sensitive information disclosure. IBM X-Force ID: 160012.
cvelistv5nvd
CVE-2018-1835HIGHCVSS 7.1v5.0v52018-11-02
CVE-2018-1835 [HIGH] CWE-611 CVE-2018-1835: IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injectio
IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150514.
cvelistv5nvd
CVE-2018-1399MEDIUMCVSS 5.4v4.1.5v5.0.1+3 more2018-02-27
CVE-2018-1399 [MEDIUM] CWE-79 CVE-2018-1399: IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5 and 5.0 is vulnerable to cross-site scripti
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138435.
cvelistv5nvd
CVE-2017-1210HIGHCVSS 7.5v4.1.5v4.1.5.1+2 more2017-10-24
CVE-2017-1210 [HIGH] CWE-20 CVE-2017-1210: IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to look legitimate. IBM X-Force ID: 123850.
cvelistv5nvd
CVE-2017-1212MEDIUMCVSS 6.5v4.1.5v4.1.5.1+2 more2017-10-24
CVE-2017-1212 [MEDIUM] CVE-2017-1212: IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of se
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of service when viewing or opening a large file. IBM X-Force ID: 123852.
cvelistv5nvd
CVE-2017-1209MEDIUMCVSS 5.4v4.1.5v4.1.5.1+2 more2017-10-24
CVE-2017-1209 [MEDIUM] CWE-79 CVE-2017-1209: IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to cross-site scr
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123849.
cvelistv5nvd
CVE-2017-1211LOWCVSS 2.5v4.1.5v4.1.5.1+2 more2017-10-24
CVE-2017-1211 [LOW] CWE-200 CVE-2017-1211: IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive inform
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled. IBM X-Force ID: 123851.
cvelistv5nvd
CVE-2017-1308MEDIUMCVSS 6.5v4.1.5v4.1.5.1+1 more2017-07-13
CVE-2017-1308 [MEDIUM] CWE-552 CVE-2017-1308: IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated atta
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.
cvelistv5nvd