Known vulnerabilities in IBM MaaS360 Cloud Extender Agent

Software CPE: cpe:2.3:a:ibm_corporation:ibm_maas360_cloud_extender_agent:*:*:*:*:*:*:*:*
Total vulnerabilities: 43
Public exploits: 4
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM MaaS360 Cloud Extender Agent IBM MaaS360 Cloud Extender Agent is affected by 43 known vulnerabilities: 1 critical, 4 high, 28 medium, 10 low Critical High Medium Low

Vulnerabilities (43)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU95131 - Out-of-bounds read
CVE-2024-7264
CWE-125 Medium
No
No
- 01.08.2024 SB2024080110
SB2024080117
SB20240805104
and 43 more
#VU82952 - Divide By Zero
CVE-2023-46849
CWE-369 Medium
No
No
3.000.300.025 10.11.2023 SB2023111004
SB2023111005
SB2023111006
and 6 more
#VU82951 - Use After Free
CVE-2023-46850
CWE-416 Low
No
No
3.000.300.025 10.11.2023 SB2023111004
SB2023111005
SB2023111006
and 6 more
#VU82349 - Cryptographic Issues
CVE-2023-5363
CWE-310 Low
No
No
3.000.300.025 24.10.2023 SB2023102443
SB2023102448
SB2023102534
and 46 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
3.000.300.025 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 651 more
#VU81726 - Integer overflow
CVE-2023-36478
CWE-190 Medium
No
No
3.000.300.025 10.10.2023 SB2023101018
SB2023102640
SB2023103106
and 53 more
#VU80793 - Improper Authorization
CVE-2023-41900
CWE-285 Low
No
No
3.000.300.025 14.09.2023 SB2023091440
SB2023092933
SB2023102621
and 29 more
#VU80792 - Improper input validation
CVE-2023-36479
CWE-20 Medium
No
No
3.000.300.025 14.09.2023 SB2023091440
SB2023092933
SB2023102621
and 48 more
#VU80791 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-40167
CWE-444 Medium
No
No
3.000.300.025 14.09.2023 SB2023091440
SB2023092933
SB2023101760
and 68 more
#VU80565 - Improper input validation
CVE-2023-4807
CWE-20 Low
No
No
3.000.300.025 08.09.2023 SB2023090834
SB2023092109
SB2023110126
and 45 more
#VU77573 - Resource exhaustion
CVE-2023-34462
CWE-400 Medium
No
No
3.000.300.025 20.06.2023 SB2023062026
SB2023072521
SB2023072539
and 98 more
#VU73831 - Exposure of sensitive information to an unauthorized actor
CVE-2023-27538
CWE-200 Medium
No
No
3.000.100.069 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 40 more
#VU73828 - State Issues
CVE-2023-27535
CWE-371 Low
No
No
3.000.100.069 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 84 more
#VU73826 - Improper input validation
CVE-2023-27533
CWE-20 Low
No
No
3.000.100.069 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 42 more
#VU71999 - NULL Pointer Dereference
CVE-2023-0401
CWE-476 Medium
No
No
3.000.100.069 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 52 more
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
3.000.100.069 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
3.000.100.069 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
3.000.100.069 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
3.000.100.069 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU70119 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2022-41915
CWE-113 Medium
No
No
3.000.100.069 12.12.2022 SB2022121215
SB2023011210
SB2023013027
and 25 more


Showing elements 1 - 20 out of 43