IBM datacap是美国IBM公司的一套文档采集与识别平台。 IBM Datacap和IBM Datacap Navigator存在跨站脚本漏洞,该漏洞源于容易受到跨站脚本攻击,可能导致未经验证的攻击者在Web UI中嵌入任意JavaScript代码,从而改变预期功能,可能导致可信会话中的凭据泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Datacap | 9.1.7≤ 1.8.4 |
affected |
9.1.8 |
affected | ||
9.1.9 |
affected | ||
| IBM | Datacap Navigator | 9.1.7≤ 8.2.1.0 |
affected |
9.1.8 |
affected | ||
9.1.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Datacap | 9.1.7 ~ 1.8.4 |
cpe:2.3:a:ibm:datacap:9.1.7:*:*:*:*:*:*:*
|
|
| IBM | Datacap Navigator | 9.1.7 ~ 8.2.1.0 |
cpe:2.3:a:ibm:datacap_navigator:9.1.7:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10561 | 10.0 CRITICAL | Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Inj |
| CVE-2026-7664 | 9.8 CRITICAL | Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS |
| CVE-2026-12628 | 9.1 CRITICAL | Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized |
| CVE-2026-9072 | 8.1 HIGH | WebSphere Application Server Remote Code Execution |
| CVE-2026-9071 | 7.5 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-8858 | 7.5 HIGH | WebSphere Application Server Remote Code Execution |
| CVE-2026-9006 | 7.4 HIGH | IBM WebSphere Application Server is affected by server-side request forgery |
| CVE-2026-8646 | 7.4 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2024-54178 | 6.5 MEDIUM | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud |
| CVE-2024-51454 | 6.5 MEDIUM | IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vuln |
| CVE-2026-7253 | 6.0 MEDIUM | IBM Sterling File Gateway SQL Injection |
| CVE-2025-2669 | 6.0 MEDIUM | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud |
| CVE-2026-9320 | 5.9 MEDIUM | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-10852 | 5.9 MEDIUM | Websphere Application Server is Affected By a Denial of Service |
| CVE-2026-8636 | 5.5 MEDIUM | Multiple Vulnerabilities in IBM Datacap |
| CVE-2026-11372 | 5.4 MEDIUM | IBM TRIRIGA Cross-Site Scripting Vulnerability |
| CVE-2025-33128 | 5.4 MEDIUM | IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vuln |
| CVE-2023-33854 | 5.3 MEDIUM | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud |
| CVE-2026-9610 | 2.3 LOW | Multiple Vulnerabilities in IBM Datacap |
| CVE-2026-10845 | IBM WebSphere Application Server is affected by an authentication bypass vulnerability |
No comments yet