| ID | CVSS | Sažetak | Zadnje ažurirano | Objavljeno |
|---|---|---|---|---|
| CVE-2020-4929 | 3.5 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste | 2021-05-07 14:41:00 | 2021-05-05 16:15:00 |
| CVE-2020-4932 | 4.6 | IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 191 | 2021-05-07 14:40:00 | 2021-05-05 16:15:00 |
| CVE-2020-4993 | 4.0 | IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks. IBM X-Force ID: 192905. | 2021-05-07 14:29:00 | 2021-05-05 16:15:00 |
| CVE-2020-5013 | 5.5 | IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 19324 | 2021-05-07 14:28:00 | 2021-05-05 16:15:00 |
| CVE-2021-20397 | 4.3 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste | 2021-05-07 14:27:00 | 2021-05-05 16:15:00 |
| CVE-2021-20401 | 4.6 | IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196 | 2021-05-07 14:19:00 | 2021-05-05 16:15:00 |
| CVE-2021-31791 | 5.0 | In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command. | 2021-05-07 14:02:00 | 2021-04-23 22:15:00 |
| CVE-2021-29239 | 4.6 | CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity. | 2021-05-07 13:54:00 | 2021-05-03 14:15:00 |
| CVE-2020-28944 | 5.0 | OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data. | 2021-05-07 13:32:00 | 2021-04-30 22:15:00 |
| CVE-2020-28945 | 4.3 | OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as 
