Known vulnerabilities in IBM Match 360 - page 2

Software: IBM Match 360
Software CPE: cpe:2.3:a:ibm_corporation:ibm_match_360:*:*:*:*:*:*:*:*
Total vulnerabilities: 40
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Match 360 IBM Match 360 is affected by 40 known vulnerabilities: 7 high, 24 medium, 9 low Critical High Medium Low

Vulnerabilities (40)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU78492 - Improper Handling of Parameters
CVE-2022-3697
CWE-233 Low
No
No
4.7.0 21.07.2023 SB2023072120
SB2023091820
SB2023120147
and 5 more
#VU72886 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-41721
CWE-444 Medium
No
No
4.7.0 06.03.2023 SB2023030655
SB2023030656
SB2023030657
and 39 more
#VU72686 - Resource exhaustion
CVE-2022-41723
CWE-400 Medium
No
No
4.7.0 01.03.2023 SB2023030130
SB2023030131
SB2023030946
and 190 more
#VU72427 - Allocation of Resources Without Limits or Throttling
CVE-2023-24998
CWE-770 Medium
Available
No
4.7.1 20.02.2023 SB2023022046
SB2023022047
SB2023030917
and 203 more
#VU72320 - Improper Privilege Management
CVE-2023-25173
CWE-269 Low
No
No
4.7.0 16.02.2023 SB2023021620
SB2023050808
SB2023051069
and 52 more
#VU72319 - Resource exhaustion
CVE-2023-25153
CWE-400 Medium
No
No
4.7.0 16.02.2023 SB2023021620
SB2023051934
SB2023060110
and 30 more
#VU72075 - Insecure Temporary File
CVE-2023-0482
CWE-377 Low
No
No
- 08.02.2023 SB2023020877
SB2023033003
SB2023033004
and 36 more
#VU70797 - Exposure of sensitive information to an unauthorized actor
CVE-2022-45787
CWE-200 Low
No
No
4.7.0 09.01.2023 SB2023010909
SB2023020878
SB2023031107
and 34 more
#VU70444 - Server-Side Request Forgery (SSRF)
CVE-2022-46364
CWE-918 Medium
No
No
4.7.0 20.12.2022 SB2022122009
SB2023011329
SB2023011707
and 67 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
4.7.0 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU70039 - Resource exhaustion
CVE-2022-23471
CWE-400 Medium
No
No
4.7.0 08.12.2022 SB2022120802
SB2022121324
SB2022122112
and 27 more
#VU69209 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-34165
CWE-444 Medium
No
No
4.5.3 10.11.2022 SB2022111029
SB2022111104
SB2022111409
and 58 more
#VU66857 - UNIX Symbolic Link (Symlink) Following
CVE-2015-3627
CWE-61 Low
No
No
4.7.0 30.08.2022 SB2015051807
SB2022083021
SB2023022316
and 7 more
#VU65906 - Exposure of sensitive information to an unauthorized actor
CVE-2022-22393
CWE-200 Low
No
No
4.5.1 01.08.2022 SB2022080110
SB2022081039
SB2022081515
and 8 more
#VU65655 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2019-10172
CWE-611 Medium
No
No
4.7.1 21.07.2022 SB2022072128
SB2021021828
SB2023042803
and 18 more
#VU64197 - Improper Authentication
CVE-2022-22475
CWE-287 Low
No
No
4.5.1 13.06.2022 SB2022061307
SB2022061310
SB2022062218
and 26 more
#VU60834 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-23450
CWE-94 High
No
No
4.0.8 23.02.2022 SB2022022311
SB2022022312
SB2022031011
and 42 more
#VU51511 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-13936
CWE-94 High
No
No
4.7.1 16.03.2021 SB2021031618
SB2021072614
SB2022011911
and 45 more
#VU29544 - Resource exhaustion
CVE-2020-14422
CWE-400 Medium
No
No
4.7.0 07.07.2020 SB2020070704
SB2020070705
SB2020070710
and 40 more
#VU21470 - Improper input validation
CVE-2019-10202
CWE-20 High
No
No
4.7.1 01.10.2019 SB2019100116
SB2019100117
SB2019100118
and 24 more


Showing elements 21 - 40 out of 40