Home/Product/ibm pureapplication system
Product

ibm pureapplication system

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-4241
>= 2.2.3.0 and <= 2.2.5.3
IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authentication an
7.8HIGH
CVE-2019-4235
>= 2.2.3.0 and <= 2.2.5.3
IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, which make
7.5HIGH
CVE-2019-4234
>= 2.2.3.0 and <= 2.2.5.3
IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. An attacke
4.3MEDIUM
CVE-2019-4225
>= 2.2.3.0 and <= 2.2.5.3
IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a l
4.4MEDIUM
CVE-2019-4224
>= 2.2.3.0 and <= 2.2.5.3
IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted
8.8HIGH
CVE-2015-0235
all versions
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows con
CVE-2014-6158
all versions
Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4 iFix 10,
CVE-2014-7169
>= 1.0.0.0 and <= 1.0.0.4
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environme
9.8CRITICAL
CVE-2014-6271
>= 1.0.0.0 and <= 1.0.0.4
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows re
9.8CRITICAL
CVE-2014-0960
all versions
IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intende
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin