Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Elusivefox

Researcher fromSTM Solutions
#20933of 53,624
11.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-18175
6.5
2020-09-04
Ibm · Ibm Infosphere Metadata Asset Manager · CVE-2020-4632
**Name of the Vulnerable Software and Affected Versions** IBM InfoSphere Metadata Asset Manager version 11.7 **Description** The issue allows a remote authenticated attacker to exploit server-side request forgery by sending a specially crafted request, potentially submitting or controlling server requests. **Recommendations** For IBM InfoSphere Metadata Asset Manager version 11.7, update to a version that includes a fix for this issue, as no specific workaround is provided in the available data.
PT-2020-18211
5.4
2020-09-04
Ibm · Ibm Infosphere Information Server · CVE-2020-4702
**Name of the Vulnerable Software and Affected Versions** IBM InfoSphere Information Server version 11.7 **Description** The issue allows users to embed arbitrary JavaScript code in the Web UI, potentially altering the intended functionality and leading to credentials disclosure within a trusted session. **Recommendations** For IBM InfoSphere Information Server version 11.7, update to a version that includes a fix for this issue to prevent stored cross-site scripting attacks. As a temporary workaround, consider restricting access to the Web UI to minimize the risk of exploitation.