CVE-2019-4000 to CVE-2019-4999
8 CVEs with public proof-of-concept exploits.
- CVE-2019-40001 PoCImproper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated…
- CVE-2019-40011 PoCImproper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.
- CVE-2019-40131 PoCIBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This…
- CVE-2019-40612 PoCsIBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets…
- CVE-2019-42792 PoCsIBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a…
- CVE-2019-43521 PoCIBM Maximo Anywhere 7.6.4.0 applications could allow obfuscation of the application source code. IBM X-Force ID: 161494.
- CVE-2019-46501 PoCIBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which…
- CVE-2019-47165 PoCsKEVIBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as…