Known vulnerabilities in DataStax Hyper-Converged Database

Software CPE: cpe:2.3:a:ibm_corporation:datastax_hyper-converged_database:*:*:*:*:*:*:*:*
Total vulnerabilities: 26
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting DataStax Hyper-Converged Database DataStax Hyper-Converged Database is affected by 26 known vulnerabilities: 4 high, 15 medium, 7 low Critical High Medium Low

Vulnerabilities (26)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113028 - Permissions, Privileges, and Access Controls
CVE-2024-56433
CWE-264 Medium
No
No
1.2.5 17.07.2025 SB2025071777
SB2025071778
SB2025071779
and 5 more
#VU111143 - Double Free
CVE-2025-5914
CWE-415 High
No
No
1.2.5 16.06.2025 SB2025061602
SB2025061603
SB2025061604
and 51 more
#VU111062 - Permissions, Privileges, and Access Controls
CVE-2025-4598
CWE-264 Low
Available
No
1.2.5 11.06.2025 SB2025061128
SB2025061134
SB2025061152
and 19 more
#VU108111 - Heap-based Buffer Overflow
CVE-2021-45941
CWE-122 Medium
No
No
1.2.5 01.05.2025 SB2022010106
SB2025050122
SB2026042816
#VU108110 - Heap-based Buffer Overflow
CVE-2021-45940
CWE-122 Medium
No
No
1.2.5 01.05.2025 SB2022010105
SB2025050122
SB2026042816
#VU107411 - Heap-based Buffer Overflow
CVE-2024-56406
CWE-122 High
Available
No
1.2.5 14.04.2025 SB2025041424
SB2025041425
SB2025041429
and 18 more
#VU105900 - Memory corruption
CVE-2025-25724
CWE-119 High
No
No
1.2.5 20.03.2025 SB2025032034
SB2025032045
SB2025032169
and 25 more
#VU103771 - Improper Authentication
CVE-2024-12797
CWE-287 Medium
No
No
1.2.5 11.02.2025 SB2025021187
SB20250211108
SB20250211159
and 58 more
#VU103289 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-12798
CWE-94 Low
No
No
1.2.5 24.01.2025 SB2025012460
SB2025012488
SB2025012495
and 28 more
#VU92195 - NULL Pointer Dereference
CVE-2023-45918
CWE-476 Medium
No
No
1.2.5 18.06.2024 SB2024061808
SB2024061809
SB2024080107
and 5 more
#VU89218 - Resource exhaustion
CVE-2024-29857
CWE-400 Medium
No
No
1.2.5 07.05.2024 SB2024050731
SB2024061019
SB20240611170
and 69 more
#VU85848 - Resource exhaustion
CVE-2023-6481
CWE-400 Medium
No
No
1.2.5 29.01.2024 SB2024012902
SB2024020727
SB2024020840
and 23 more
#VU85618 - Deserialization of Untrusted Data
CVE-2023-6378
CWE-502 Medium
No
No
1.2.5 19.01.2024 SB2024011926
SB2024011927
SB2024012316
and 39 more
#VU77573 - Resource exhaustion
CVE-2023-34462
CWE-400 Medium
No
No
1.2.5 20.06.2023 SB2023062026
SB2023072521
SB2023072539
and 98 more
#VU77107 - Incorrect Default Permissions
CVE-2023-2976
CWE-276 Low
No
No
1.2.5 08.06.2023 SB2023060849
SB2023071712
SB2023072512
and 157 more
#VU73782 - NULL Pointer Dereference
CVE-2022-3606
CWE-476 Low
No
No
1.2.5 17.03.2023 SB2023031716
SB2023031725
SB2023031726
and 8 more
#VU64274 - Out-of-bounds read
CVE-2022-29458
CWE-125 Medium
No
No
1.2.5 14.06.2022 SB2022061418
SB2022061419
SB2022072842
and 29 more
#VU59358 - Uncontrolled Recursion
CVE-2021-3997
CWE-674 Low
No
No
1.2.5 10.01.2022 SB2022011041
SB2022011194
SB2022011325
and 10 more
#VU50139 - Incorrect Default Permissions
CVE-2020-8908
CWE-276 Low
No
No
1.2.5 11.12.2020 SB2020121114
SB2021031707
SB2021042104
and 62 more
#VU27519 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11023
CWE-79 Low
Available
Exploited
1.2.5 05.05.2020 SB2020042126
SB2020052033
SB2020052103
and 180 more


Showing elements 1 - 20 out of 26