Known vulnerabilities in IBM Netcool Agile Service Manager

Software CPE: cpe:2.3:a:ibm_corporation:ibm_netcool_agile_service_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 23
Public exploits: 5
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Netcool Agile Service Manager IBM Netcool Agile Service Manager is affected by 23 known vulnerabilities: 1 critical, 2 high, 19 medium, 1 low Critical High Medium Low

Vulnerabilities (23)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU61255 - Incorrect Regular Expression
CVE-2021-23362
CWE-185 Medium
No
No
1.1.13 11.03.2022 SB2021032315
SB2022031104
SB2022060315
and 28 more
#VU59551 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-21824
CWE-94 Medium
No
No
1.1.13 12.01.2022 SB2022011216
SB2022041205
SB2022060315
and 39 more
#VU59550 - Improper Certificate Validation
CVE-2021-44533
CWE-295 Medium
No
No
1.1.13 12.01.2022 SB2022011216
SB2022041522
SB2022042517
and 36 more
#VU59549 - Improper Validation of Certificate with Host Mismatch
CVE-2021-44532
CWE-297 Medium
No
No
1.1.13 12.01.2022 SB2022011216
SB2022041522
SB2022042806
and 36 more
#VU59234 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-22960
CWE-444 Medium
No
No
1.1.13 05.01.2022 SB2022010523
SB2022010524
SB2022042806
and 40 more
#VU59233 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-22959
CWE-444 Medium
No
No
1.1.13 05.01.2022 SB2022010523
SB2022010524
SB2022011841
and 43 more
#VU59098 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44832
CWE-94 Medium
No
No
1.1.10 28.12.2021 SB2021122816
SB2021123002
SB2022010601
and 197 more
#VU55560 - Use After Free
CVE-2021-22930
CWE-416 High
No
No
1.1.13 03.08.2021 SB2021080320
SB2021080324
SB2021080325
and 35 more
#VU54625 - Incorrect Default Permissions
CVE-2021-22921
CWE-276 Low
No
No
1.1.13 08.07.2021 SB2021100417
SB2022031104
SB2022060315
and 7 more
#VU54624 - Out-of-bounds read
CVE-2021-22918
CWE-125 Medium
No
No
1.1.13 08.07.2021 SB2021070819
SB2021072009
SB2021081123
and 40 more
#VU52909 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7774
CWE-94 Medium
No
No
1.1.13 06.05.2021 SB2020111735
SB2021050615
SB2021092814
and 24 more
#VU51733 - NULL Pointer Dereference
CVE-2021-3449
CWE-476 Medium
Available
No
1.1.13 25.03.2021 SB2021032518
SB2021032602
SB2021032617
and 56 more
#VU51732 - Security Features
CVE-2021-3450
CWE-254 Medium
No
No
1.1.13 25.03.2021 SB2021032518
SB2021032602
SB2021032617
and 50 more
#VU52194 - Incorrect Regular Expression
CVE-2021-27290
CWE-185 Medium
No
No
1.1.13 12.03.2021 SB2021041364
SB2021070819
SB2021101939
and 32 more
#VU50955 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2021-22884
CWE-350 Medium
No
No
1.1.13 25.02.2021 SB2021022530
SB2021022532
SB2021022616
and 38 more
#VU50954 - Resource Management Errors
CVE-2021-22883
CWE-399 Medium
No
No
1.1.13 25.02.2021 SB2021022530
SB2021022532
SB2021022614
and 36 more
#VU50745 - Improper input validation
CVE-2021-23840
CWE-20 Medium
No
No
1.1.13 17.02.2021 SB2021021702
SB2021021817
SB2021022420
and 83 more
#VU49254 - Use After Free
CVE-2020-8265
CWE-416 Medium
No
No
1.1.13 04.01.2021 SB2021010419
SB2021010704
SB2021010705
and 33 more
#VU49253 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-8287
CWE-444 Medium
Available
No
1.1.13 04.01.2021 SB2021010419
SB2021010706
SB2021010707
and 33 more
#VU48896 - NULL Pointer Dereference
CVE-2020-1971
CWE-476 Medium
Available
No
1.1.13 08.12.2020 SB2020120852
SB2020120903
SB2020120905
and 91 more


Showing elements 1 - 20 out of 23