IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NIBM Integrated Analytics System
APPIbm1.0.0.0 – 1.0.32.0 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje
Powiązane podatności
CVE-2025-36174HIGH8.0ten sam produkt
IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file wi...
CVE-2025-36271MEDIUM5.9ten sam produkt
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms th...
CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓ten sam vendor
RCE przez YAML deserialization w IBM Aspera Faspex
CVE-2020-4427CRITICAL9.8⚠ KEVPL ✓ten sam vendor
IBM Data Risk Manager — pominięcie uwierzytelnienia SAML (Auth Bypass)
CVE-2020-4428CRITICAL9.1⚠ KEVPL ✓ten sam vendor
Command Injection w IBM Data Risk Manager umożliwiający RCE