IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. Required action: Apply updates per vendor instructions.
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands Required action: Apply updates per vendor instructions.
CVE-2015-7450EPSS 97.7%IBMWebSphere Application Server and Server Hypervisor Edition
IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system. Required action: Apply updates per vendor instructions.
IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. Required action: Apply updates per vendor instructions.
IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.� Required action: Apply updates per vendor instructions.
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. Required action: Apply updates per vendor instructions.