Ibm Smartcloud Analytics vulnerabilities

5 known vulnerabilities affecting ibm/smartcloud_analytics.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2019-4244CRITICALCVSS 9.1v1.3.1v1.3.2+3 more2019-12-10
CVE-2019-4244 [CRITICAL] CWE-306 CVE-2019-4244: IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized info IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-Force ID: 159518.
cvelistv5nvd
CVE-2019-4215MEDIUMCVSS 6.1v1.3.1v1.3.2+3 more2019-11-22
CVE-2019-4215 [MEDIUM] CWE-1021 CVE-2019-4215: IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking ac IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 159186.
cvelistv5nvd
CVE-2019-4243MEDIUMCVSS 4.4v1.3.1v1.3.2+3 more2019-11-22
CVE-2019-4243 [MEDIUM] CVE-2019-4243: IBM SmartCloud Analytics 1.3.1 through 1.3.5 allows unauthorized disclosure of information like acce IBM SmartCloud Analytics 1.3.1 through 1.3.5 allows unauthorized disclosure of information like accessing solrconfig.xml and could allow an attacker to perform disruptive administrator tasks. IBM X-Force ID: 159517.
cvelistv5nvd
CVE-2019-4216MEDIUMCVSS 4.6v1.3.1v1.3.2+3 more2019-11-22
CVE-2019-4216 [MEDIUM] CWE-74 CVE-2019-4216: IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM X-Force ID: 159187.
cvelistv5nvd
CVE-2019-4214LOWCVSS 3.7v1.3.1v1.3.2+3 more2019-11-22
CVE-2019-4214 [LOW] CWE-311 CVE-2019-4214: IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization toke IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159185.
cvelistv5nvd