Medium - CVE-2024-49793 - IBM ApplinX 11.1 is vulnerable to cross-site...
IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...
Medium - CVE-2024-49794 - IBM ApplinX 11.1 is vulnerable to cross-site...
IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Medium - CVE-2024-49795 - IBM ApplinX 11.1 is vulnerable to cross-site...
IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Medium - CVE-2024-49796 - IBM ApplinX 11.1 could allow a remote attacker...
IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability...
Medium - CVE-2024-49797 - IBM ApplinX 11.1 could allow a remote attacker...
IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability...
Medium - CVE-2024-49798 - IBM ApplinX 11.1 could allow a remote attacker...
IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks...
High - CVE-2024-49814 - IBM Security Verify Access Appliance 10.0.0...
IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.
Critical - CVE-2024-51450 - IBM Security Verify Directory 10.0.0 through...
IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.