Known vulnerabilities in FlashSystem 900 9840-AE2 and 9843-AE2

Software CPE: cpe:2.3:h:ibm_corporation:flashsystem_900_9840-ae2_and_9843-ae2:*:*:*:*:*:*:*:*
Total vulnerabilities: 74
Public exploits: 7
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FlashSystem 900 9840-AE2 and 9843-AE2 FlashSystem 900 9840-AE2 and 9843-AE2 is affected by 74 known vulnerabilities: 1 critical, 14 high, 31 medium, 28 low Critical High Medium Low

Vulnerabilities (74)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU89648 - Cryptographic Issues
CVE-2015-2730
CWE-310 Low
No
No
1.2.1.9, 1.3.0.5, 1.4.0.10 20.05.2024 SB2024052008
SB2016050813
#VU89608 - Improper Privilege Management
CVE-2018-1495
CWE-269 Low
No
No
1.3.0.10, 1.4.8.0, 1.5.1.1 17.05.2024 SB2024051706
#VU89607 - Improper Authentication
CVE-2018-1822
CWE-287 High
No
No
1.4.8.1, 1.5.0.0 17.05.2024 SB2024051705
#VU87536 - Cross-Site Request Forgery (CSRF)
CVE-2015-5351
CWE-352 Medium
No
No
1.3.0.6, 1.4.3.0 14.03.2024 SB2016021201
SB2024051523
SB2024052012
and 5 more
#VU87535 - Session Fixation
CVE-2015-5346
CWE-384 High
No
No
1.3.0.6, 1.4.3.0 14.03.2024 SB2016021201
SB2024051523
SB2024052012
and 6 more
#VU87534 - Permissions, Privileges, and Access Controls
CVE-2016-0763
CWE-264 Medium
No
No
1.3.0.6, 1.4.3.0 14.03.2024 SB2016021201
SB2024051523
SB2024052012
and 6 more
#VU18947 - Resource exhaustion
CVE-2019-11479
CWE-400 Medium
No
No
- 01.07.2019 SB2019061702
SB2019070105
SB2019061811
and 48 more
#VU18946 - Resource exhaustion
CVE-2019-11478
CWE-400 Medium
No
No
- 01.07.2019 SB2019061702
SB2019070105
SB2019061811
and 49 more
#VU18813 - Integer overflow
CVE-2019-11477
CWE-190 Medium
No
No
- 17.06.2019 SB2019061702
SB2019070105
SB2019061811
and 53 more
#VU33427 - Improper Access Control
CVE-2019-2602
CWE-284 Medium
No
No
- 23.04.2019 SB2019060321
SB2019052329
SB2019052330
and 21 more
#VU15156 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-11784
CWE-601 Low
Available
No
- 05.10.2018 SB2018100401
SB2018102605
SB2018110806
and 13 more
#VU13889 - Heap-based Buffer Overflow
CVE-2017-17833
CWE-122 High
No
No
- 16.07.2018 SB2018040907
SB2018071610
SB2018080104
and 10 more
#VU10678 - Use After Free
CVE-2017-18017
CWE-416 Medium
No
No
- 21.02.2018 SB2018022308
SB2018022309
SB2018022017
and 17 more
#VU9769 - Exposure of sensitive information to an unauthorized actor
CVE-2017-17449
CWE-200 Low
No
No
- 26.12.2017 SB2017122601
SB2017122211
SB2017122105
and 18 more
#VU639 - Improper Access Control
CVE-2016-2107
CWE-284 High
Available
No
- 23.09.2016 SB2016050504
SB2016061413
SB2016050514
and 19 more
#VU264 - Improper Control of Generation of Code ('Code Injection')
CVE-2016-0714
CWE-94 Low
No
No
1.3.0.6, 1.4.3.0 05.08.2016 SB2016021201
SB2016032101
SB2016032903
and 8 more
#VU263 - Exposure of sensitive information to an unauthorized actor
CVE-2016-0706
CWE-200 Low
No
No
1.3.0.6, 1.4.3.0 05.08.2016 SB2016021201
SB2016032101
SB2016032903
and 8 more
#VU262 - Exposure of sensitive information to an unauthorized actor
CVE-2015-5345
CWE-200 Low
No
No
1.3.0.6, 1.4.3.0 05.08.2016 SB2016021201
SB2016032101
SB2016032903
and 8 more
#VU261 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2015-5174
CWE-22 Low
No
No
1.3.0.6, 1.4.3.0 05.08.2016 SB2016021201
SB2016032101
SB2016032903
and 8 more
#VU90 - Exposure of sensitive information to an unauthorized actor
CVE-2015-2808
CWE-200 Medium
No
No
1.3.0.2 05.07.2016 SB2015040102
SB2015040103
SB2023011274
and 27 more


Showing elements 1 - 20 out of 74