Vulnerabilities (CVE)

Filtered by CWE-200
Total 9301 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20307 1 Pulsesecure 1 Virtual Traffic Manager 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.
CVE-2018-20170 1 Openstack 1 Keystone 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is a hardening opportunity, and not necessarily an issue that should have an OpenStack Security Advisory
CVE-2018-20154 1 Designmodo 1 Wp Maintenance Mode 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.
CVE-2018-20151 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 5.0 MEDIUM 7.5 HIGH
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.
CVE-2018-20073 1 Google 1 Chrome 2024-11-21 2.1 LOW 5.5 MEDIUM
Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem.
CVE-2018-1999 1 Ibm 2 Business Automation Workflow, Business Process Manager 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 154889.
CVE-2018-1993 1 Ibm 1 Spectrum Scale 2024-11-21 2.1 LOW 4.0 MEDIUM
IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.
CVE-2018-1991 1 Ibm 1 Api Connect 2024-11-21 4.0 MEDIUM 2.7 LOW
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.
CVE-2018-1990 1 Ibm 1 Cloud App Management 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration information using a specially crafted HTTP request. IBM X-Force ID: 154283.
CVE-2018-1976 1 Ibm 1 Api Connect 2024-11-21 4.0 MEDIUM 4.9 MEDIUM
IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow a user with administrative privileges to obtain highly sensitive information. IBM X-Force ID: 154031.
CVE-2018-1968 1 Ibm 1 Security Identity Manager Virtual Appliance 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153749.
CVE-2018-1961 1 Ibm 1 Emptoris Contract Management 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from error messages. IBM X-Force ID: 153657.
CVE-2018-1957 1 Ibm 1 Websphere Application Server 2024-11-21 2.1 LOW 4.0 MEDIUM
IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.
CVE-2018-1950 1 Ibm 1 Security Identity Governance And Intelligence 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance generates an error message that includes sensitive information about its environment, users, or associated data which could be used in further attacks against the system. IBM X-Force ID: 153430.
CVE-2018-1949 1 Ibm 1 Security Identity Governance And Intelligence 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153429.
CVE-2018-1935 1 Ibm 1 Connections 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request error messages. IBM X-Force ID: 153315.
CVE-2018-1932 1 Ibm 1 Api Connect 2024-11-21 4.0 MEDIUM 4.9 MEDIUM
IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the management server that could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 153175.
CVE-2018-1929 1 Ibm 1 Rational Engineering Lifecycle Manager 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 could allow a malicious user to be allowed to view any view if he knows the URL link of a the view, and access information that should not be able to see. IBM X-Force ID: 153120.
CVE-2018-1917 1 Ibm 2 Infosphere Information Server, Infosphere Information Server On Cloud 2024-11-21 4.0 MEDIUM 3.5 LOW
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.
CVE-2018-1902 1 Ibm 1 Websphere Application Server 2024-11-21 4.0 MEDIUM 3.1 LOW
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information which could be used to launch further attacks against the system. IBM X-Force ID: 152531.