IBM Watson Query是美国国际商业机器(IBM)公司的一个通用查询引擎。可以跨数据库、数据仓库、数据湖和流数据执行分布式和虚拟化查询,而无需额外的手动更改、数据移动或复制。 IBM Watson Query存在安全漏洞,该漏洞源于数据保护机制不当,可能允许经过身份验证的用户从使用Watson Query发布的对象中获取敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Data Virtualization | 1.8, 2.0, 2.1, 2.2, 3.0.0 |
cpe:2.3:a:ibm:data_virtualization_on_cloud_pak_for_data:1.8.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-28786 | 6.5 MEDIUM | IBM QRadar SIEM information disclosure |
| CVE-2023-52292 | 6.4 MEDIUM | IBM Sterling File Gateway cross-site scripting |
| CVE-2024-38325 | 5.9 MEDIUM | IBM Storage Defender information disclosure |
| CVE-2024-38320 | 5.9 MEDIUM | IBM Storage Protect for Virtual Environments: Data Protection for VMware information discl |
| CVE-2024-27256 | 5.9 MEDIUM | IBM MQ Operator information disclosure |
| CVE-2023-46187 | 5.4 MEDIUM | IBM InfoSphere Master Data Management cross-site scripting |
| CVE-2024-37527 | 5.4 MEDIUM | IBM OpenPages with Watson cross-site scripting |
| CVE-2024-28771 | 4.8 MEDIUM | IBM Security Directory Integrator information disclosure |
| CVE-2024-28770 | 4.8 MEDIUM | IBM Security Directory Integrator information disclosure |
| CVE-2024-22316 | 4.3 MEDIUM | IBM Sterling File Gateway improper access control |
| CVE-2023-47159 | 4.3 MEDIUM | IBM Sterling File Gateway information disclosure |
| CVE-2024-28766 | 2.4 LOW | IBM Security Directory Integrator information disclosure |
No comments yet