Known vulnerabilities in Operational Decision Manager - page 3
Vendor:
IBM Corporation
Software:
Operational Decision Manager
Software CPE:
cpe:2.3:a:ibm_corporation:operational_decision_manager:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
188
Public exploits:
20
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
9.5.0.1 Interim fix 5
9.0.0.1 Interim fix 22
8.12.0.1 Interim fix 37
8.11.1 Interim fix 53
8.11.0.1 Interim fix 54
9.0.0.0
9.5.0.0 Interim fix 7
9.0.0.1 Interim fix 15
8.12.0.1 Interim fix 31
8.11.1 Interim fix 47
8.11.0.1 Interim fix 49
9.5.0.0 Interim fix 2
9.0.0.1 Interim fix 11
8.12.0.1 Interim fix 28
8.11.1 Interim fix 44
8.11.0.1 Interim fix 46
9.5.0
9.0.0.1
8.12.0.1
8.11.1.0
8.11.0.1
9.0.0.0 Interim fix 6
9.0.0.0 Interim fix 5
9.0.0.0 Interim fix 3
9.0.0.0 Interim fix 1
9.0.0.1 Interim fix 7
8.12.0.1 Interim fix 24
8.11.1.0 Interim fix 39
8.11.0.1 Interim fix 42
9.0.0.1 Interim fix 4
8.12.0.1 Interim fix 15
8.11.1 Interim fix 31
8.11.0.1 Interim fix 36
9.0.0.1 Interim fix 2
8.12.0.1 Interim fix 18
8.11.1 Interim fix 34
8.11.0.1 Interim fix 039
8.11.0.1 Interim fix 037
9.0.0.0 Interim fix 2
8.12.0.1 Interim fix 13
8.11.1 Interim fix 28
8.11.0.1 Interim fix 34
8.12.0.1 Interim fix 10
8.11.1 Interim fix 25
8.11.0.1 Interim fix 32
8.10.5.2 Interim fix 1
8.11.0.1 Interim fix 30
8.11.1 Interim fix 24
8.12.0.1 Interim fix 5
8.12.0.1 Interim fix 3
8.11.1 Interim fix 21
8.11.0.1 Interim fix 29
8.10.5.1 Interim fix 54
8.11.0.1 Interim fix 18
8.11.1 Interim fix 7
8.10.5.1 Interim fix 36
8.12.0.1 Interim fix 2
8.11.1 Interim fix 20
8.11.0.1 Interim fix 28
8.10.5.1 Interim fix 53
8.12.0.1 Interim fix 1
8.11.1 Interim fix 19
8.11.0.1 Interim fix 27
8.10.5.1 Interim fix 51
8.12.0 Interim fix 8
8.11.0.1 Interim fix 26
8.10.5.1 Interim fix 49
8.12.0 Interim fix 6
8.11.1 Interim fix 15
8.11.0.1 Interim fix 25
8.10.5.1 Interim fix 47
8.12.0 Interim fix 5
8.11.1 Interim fix 13
8.11.0.1 Interim fix 24
8.10.5.1 Interim fix 44
8.12.0 Interim fix 4
8.11.1 Interim fix 12
8.11.0.1 Interim fix 23
8.10.5.1 Interim fix 43
8.12.0 Interim fix 2
8.11.1 Interim fix 10
8.10.5.1 Interim fix 41
8.12.0 Interim fix 1
8.11.1 Interim fix 9
8.11.0.1 Interim fix 21
8.10.5.1 Interim fix 39
8.11.1 Interim fix 8
8.11.0.1 Interim fix 20
8.10.5.1 Interim fix 38
8.11.1 Interim fix 5
8.11.0.1 Interim fix 17
8.10.5.1 Interim fix 34
8.11.1 Interim fix 4
8.11.0.1 Interim fix 15
8.10.5.1 Interim fix 33
8.11
8.10.5.1
8.10.5
8.10.4
7.5
8.0
8.5
8.9.2.1
8.8.1.3
8.7.1.2
8.6.0.3
8.9
8.8
8.7
8.6
Vulnerabilities (188)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU89622 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) CVE-2021-29245 |
CWE-338 | Medium | 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5 | 17.05.2024 |
SB2024051717 |
||
| #VU89618 - Incorrect Permission Assignment for Critical Resource CVE-2021-21364 |
CWE-732 | Low | 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5 | 17.05.2024 |
SB2024051717 |
||
| #VU86800 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2023-4218 |
CWE-611 | Low | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 26.02.2024 |
SB2024022642 SB2024030105 SB2024032906 and 11 more |
||
| #VU86625 - Resource exhaustion CVE-2024-26308 |
CWE-400 | Medium | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 20.02.2024 |
SB2024022033 SB2024022937 SB2024031520 and 138 more |
||
| #VU86624 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-25710 |
CWE-835 | Medium | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 20.02.2024 |
SB2024022033 SB2024022937 SB2024031520 and 102 more |
||
| #VU83545 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') CVE-2022-46337 |
CWE-90 | High | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 28.11.2023 |
SB2023112861 SB2024011806 SB2024020107 and 34 more |
||
| #VU70524 - Out-of-bounds write CVE-2022-41854 |
CWE-787 | Medium | 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5 | 28.12.2022 |
SB2022122813 SB2022122926 SB2023010417 and 52 more |
||
| #VU67668 - Stack-based buffer overflow CVE-2022-38750 |
CWE-121 | Medium | 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5 | 27.09.2022 |
SB2022092714 SB2022092728 SB2022100555 and 50 more |
||
| #VU67666 - Stack-based buffer overflow CVE-2022-38749 |
CWE-121 | Medium | 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5 | 27.09.2022 |
SB2022092714 SB2022092728 SB2022100555 and 51 more |
||
| #VU67663 - Out-of-bounds write CVE-2022-38751 |
CWE-787 | Medium | 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5 | 27.09.2022 |
SB2022092714 SB2022092728 SB2022100555 and 50 more |
||
| #VU54854 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2021-35515 |
CWE-835 | Medium | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 14.07.2021 |
SB2021071408 SB2021080809 SB2021100411 and 23 more |
||
| #VU54853 - Resource exhaustion CVE-2021-36090 |
CWE-400 | Medium | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 14.07.2021 |
SB2021071408 SB2021080809 SB2021100411 and 70 more |
||
| #VU54852 - Resource exhaustion CVE-2021-35517 |
CWE-400 | Medium | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 14.07.2021 |
SB2021071408 SB2021080809 SB2021100411 and 33 more |
||
| #VU54851 - Resource exhaustion CVE-2021-35516 |
CWE-400 | Medium | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 14.07.2021 |
SB2021071408 SB2021080809 SB2021100411 and 21 more |
||
| #VU28304 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-11077 |
CWE-444 | Medium | 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5 | 28.05.2020 |
SB2020052803 SB2020071806 SB2020071902 and 4 more |
||
| #VU25747 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2020-5247 |
CWE-113 | Medium | 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5 | 03.03.2020 |
SB2020030309 SB2024051717 SB2020033146 and 2 more |
||
| #VU22545 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2019-12415 |
CWE-611 | High | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 06.11.2019 |
SB2019110635 SB2020012308 SB2020012309 and 42 more |
||
| #VU22185 - Resource Management Errors CVE-2019-12402 |
CWE-399 | Medium | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 23.10.2019 |
SB2019083014 SB2020042210 SB2020071665 and 13 more |
||
| #VU12420 - Permissions, Privileges, and Access Controls CVE-2018-1313 |
CWE-264 | Low | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 08.05.2018 |
SB2018050809 SB2022110302 SB2023040530 and 8 more |
||
| #VU735 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2015-1832 |
CWE-611 | Low | 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10 | 04.10.2016 |
SB2015071704 SB2020042337 SB2020102845 and 6 more |
Showing elements 41 - 60 out of 188