Known vulnerabilities in IBM UrbanCode Release - page 2

Software CPE: cpe:2.3:a:ibm_corporation:ibm_urbancode_release:*:*:*:*:*:*:*:*
Total vulnerabilities: 46
Public exploits: 9
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM UrbanCode Release IBM UrbanCode Release is affected by 46 known vulnerabilities: 1 critical, 4 high, 33 medium, 8 low Critical High Medium Low

Vulnerabilities (46)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU81803 - Exposed Dangerous Method or Function
CVE-2023-42794
CWE-749 Medium
No
No
7.0.0 10.10.2023 SB2023101084
SB2023101286
SB2023111528
and 22 more
#VU81799 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-45648
CWE-444 Medium
No
No
7.0.0 10.10.2023 SB2023101084
SB2023101122
SB2023101123
and 47 more
#VU80089 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-41080
CWE-601 Medium
Available
No
6.2.5.11 29.08.2023 SB2023082924
SB2023100565
SB2023101122
and 51 more
#VU77622 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34981
CWE-200 Medium
No
No
6.2.5.11 22.06.2023 SB2023062241
SB2023070714
SB2023071901
and 24 more
#VU76417 - Allocation of Resources Without Limits or Throttling
CVE-2023-28709
CWE-770 Medium
No
No
6.2.5.11 22.05.2023 SB2023052235
SB2023053003
SB2023053052
and 35 more
#VU75431 - Uncontrolled Recursion
CVE-2023-1436
CWE-674 Medium
No
No
6.2.5.11 24.04.2023 SB2023042409
SB2023042411
SB2023050111
and 86 more
#VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-28708
CWE-614 Low
No
No
6.2.5.11 22.03.2023 SB2023032237
SB2023032939
SB2023032945
and 53 more
#VU72427 - Allocation of Resources Without Limits or Throttling
CVE-2023-24998
CWE-770 Medium
Available
No
6.2.5.11 20.02.2023 SB2023022046
SB2023022047
SB2023030917
and 202 more
#VU71109 - Out-of-bounds write
CVE-2022-45693
CWE-787 Medium
No
No
6.2.5.11 11.01.2023 SB2023011159
SB2023011160
SB2023013112
and 45 more
#VU71108 - Out-of-bounds write
CVE-2022-45685
CWE-787 Medium
No
No
6.2.5.11 11.01.2023 SB2023011159
SB2023011160
SB2023030328
and 29 more
#VU70666 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-45143
CWE-94 Medium
No
No
6.2.5.8 03.01.2023 SB2023010329
SB2023012516
SB2023012606
and 34 more
#VU69674 - Resource exhaustion
CVE-2022-40150
CWE-400 Medium
No
No
6.2.5.11 29.11.2022 SB2022112909
SB2022112941
SB2022121101
and 46 more
#VU69673 - Out-of-bounds write
CVE-2022-40149
CWE-787 Medium
No
No
6.2.5.11 29.11.2022 SB2022112909
SB2022112941
SB2022121101
and 41 more
#VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-42252
CWE-444 Medium
No
No
6.2.5.8 31.10.2022 SB2022103146
SB2022112324
SB2022112533
and 43 more
#VU67714 - Exposure of sensitive information to an unauthorized actor
CVE-2021-43980
CWE-200 Low
No
No
6.2.5.8 28.09.2022 SB2022092818
SB2022103001
SB2022111642
and 20 more
#VU65655 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2019-10172
CWE-611 Medium
No
No
6.2.5.11 21.07.2022 SB2022072128
SB2021021828
SB2023042803
and 18 more
#VU64627 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-34305
CWE-79 Medium
Available
No
6.2.5.8 23.06.2022 SB2022062338
SB2022071177
SB2022071801
and 26 more
#VU63225 - Data Handling
CVE-2022-29885
CWE-19 Low
Available
No
6.1.7.5 16.05.2022 SB2022051612
SB2022072044
SB20220720107
and 19 more
#VU51511 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-13936
CWE-94 High
No
No
6.2.5.11 16.03.2021 SB2021031618
SB2021072614
SB2022011911
and 45 more
#VU21470 - Improper input validation
CVE-2019-10202
CWE-20 High
No
No
6.2.5.11 01.10.2019 SB2019100116
SB2019100117
SB2019100118
and 24 more


Showing elements 21 - 40 out of 46