Ibm Entirex vulnerabilities
13 known vulnerabilities affecting ibm/entirex.
Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4LOW8
Vulnerabilities
Page 1 of 1
CVE-2024-56812MEDIUMCVSS 5.5v11.12025-02-27
CVE-2024-56812 [LOW] CWE-209 CVE-2024-56812: IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2024-54170MEDIUMCVSS 5.5v11.12025-02-27
CVE-2024-54170 [MEDIUM] CWE-1333 CVE-2024-54170: IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expre
IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expression with an inefficient complexity that consumes excessive CPU cycles.
cvelistv5nvd
CVE-2024-54169MEDIUMCVSS 6.5v11.12025-02-27
CVE-2024-54169 [MEDIUM] CWE-22 CVE-2024-54169: IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An att
IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
cvelistv5nvd
CVE-2024-56493LOWCVSS 3.3v11.12025-02-27
CVE-2024-56493 [LOW] CWE-209 CVE-2024-56493: IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2024-56810LOWCVSS 3.3v11.12025-02-27
CVE-2024-56810 [LOW] CWE-209 CVE-2024-56810: IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2024-56494LOWCVSS 3.3v11.12025-02-27
CVE-2024-56494 [LOW] CWE-209 CVE-2024-56494: IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2024-56496LOWCVSS 3.3v11.12025-02-27
CVE-2024-56496 [LOW] CWE-209 CVE-2024-56496: IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2025-0759LOWCVSS 3.3v11.12025-02-27
CVE-2025-0759 [LOW] CWE-367 CVE-2025-0759: IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to
IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared resource synchronization.
cvelistv5nvd
CVE-2024-56495LOWCVSS 3.3v11.12025-02-27
CVE-2024-56495 [LOW] CWE-209 CVE-2024-56495: IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2024-56811LOWCVSS 3.3v11.12025-02-27
CVE-2024-56811 [LOW] CWE-209 CVE-2024-56811: IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2024-54171HIGHCVSS 7.1v11.12025-02-06
CVE-2024-54171 [HIGH] CWE-611 CVE-2024-54171: IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML
IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
cvelistv5nvd
CVE-2025-0158MEDIUMCVSS 5.5v11.12025-02-06
CVE-2025-0158 [MEDIUM] CWE-248 CVE-2025-0158: IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and
IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.
cvelistv5nvd
CVE-2024-56467LOWCVSS 3.3v11.12025-02-06
CVE-2024-56467 [LOW] CWE-209 CVE-2024-56467: IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
cvelistv5nvd