Ibm Powersc vulnerabilities
13 known vulnerabilities affecting ibm/powersc.
Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2023-50940CRITICALCVSS 9.8v1.3v2.0+2 more2024-02-02
CVE-2023-50940 [MEDIUM] CWE-942 CVE-2023-50940: IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacke
IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 275130.
cvelistv5nvd
CVE-2023-50326HIGHCVSS 7.5v1.3v2.0+2 more2024-02-02
CVE-2023-50326 [HIGH] CWE-307 CVE-2023-50326: IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote a
IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107.
cvelistv5nvd
CVE-2023-50937HIGHCVSS 7.5v1.3v2.0+2 more2024-02-02
CVE-2023-50937 [MEDIUM] CWE-327 CVE-2023-50937: IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an
IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275117.
cvelistv5nvd
CVE-2023-50936HIGHCVSS 8.8v1.3v2.0+2 more2024-02-02
CVE-2023-50936 [MEDIUM] CWE-613 CVE-2023-50936: IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenti
IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 275116.
cvelistv5nvd
CVE-2023-50939HIGHCVSS 7.5v1.3v2.0+2 more2024-02-02
CVE-2023-50939 [MEDIUM] CWE-327 CVE-2023-50939: IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an
IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275129.
cvelistv5nvd
CVE-2023-50962HIGHCVSS 7.5v1.3v2.0+2 more2024-02-02
CVE-2023-50962 [MEDIUM] CWE-319 CVE-2023-50962: IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web
IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004.
cvelistv5nvd
CVE-2023-50934MEDIUMCVSS 5.3v1.3v2.0+2 more2024-02-02
CVE-2023-50934 [MEDIUM] CWE-308 CVE-2023-50934: IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk o
IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a dual-factor authentication scheme. IBM X-Force ID: 275114.
cvelistv5nvd
CVE-2023-50933MEDIUMCVSS 6.1v1.3v2.0+2 more2024-02-02
CVE-2023-50933 [MEDIUM] CWE-79 CVE-2023-50933: IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malici
IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 275113.
cvelistv5nvd
CVE-2023-50941MEDIUMCVSS 5.4v1.3v2.0+2 more2024-02-02
CVE-2023-50941 [MEDIUM] CWE-384 CVE-2023-50941: IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authentica
IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation. IBM X-Force ID: 275131.
cvelistv5nvd
CVE-2023-50327MEDIUMCVSS 5.3v1.3v2.0+2 more2024-02-02
CVE-2023-50327 [MEDIUM] CWE-650 CVE-2023-50327: IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perf
IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized file request modification. IBM X-Force ID: 275109.
cvelistv5nvd
CVE-2023-50938MEDIUMCVSS 4.3v1.3v2.0+2 more2024-02-02
CVE-2023-50938 [MEDIUM] CWE-451 CVE-2023-50938: IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the vic
IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 275128.
cvelistv5nvd
CVE-2023-50935MEDIUMCVSS 6.5v1.3v2.0+2 more2024-02-02
CVE-2023-50935 [MEDIUM] CWE-425 CVE-2023-50935: IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allo
IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized access to application functionality and/or resources. IBM X-Force ID: 275115.
cvelistv5nvd
CVE-2023-50328MEDIUMCVSS 5.3v1.3v2.0+2 more2024-02-02
CVE-2023-50328 [LOW] CWE-598 CVE-2023-50328: IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL
IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.
cvelistv5nvd