Known vulnerabilities in QRadar Pulse App - page 2

Software CPE: cpe:2.3:a:ibm_corporation:qradar_pulse_app:*:*:*:*:*:ibm_qradar_siem:*:*
Total vulnerabilities: 47
Public exploits: 7
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting QRadar Pulse App QRadar Pulse App is affected by 47 known vulnerabilities: 5 high, 33 medium, 9 low Critical High Medium Low

Vulnerabilities (47)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73793 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-43441
CWE-94 High
No
No
2.2.10 17.03.2023 SB2023031738
SB2023031741
SB2023053113
and 1 more
#VU72750 - Inefficient Algorithmic Complexity
CVE-2022-25881
CWE-407 Medium
No
No
2.2.10 03.03.2023 SB2023030326
SB2023030328
SB2023031112
and 61 more
#VU66955 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7788
CWE-94 Medium
No
No
2.2.9 05.09.2022 SB2020121120
SB2022090501
SB2022091209
and 21 more
#VU64034 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3918
CWE-94 High
No
No
2.2.9 07.06.2022 SB2021111302
SB2022060836
SB2022071504
and 45 more
#VU64011 - Improper input validation
CVE-2018-25031
CWE-20 Low
Available
No
2.2.9 07.06.2022 SB2022060710
SB2022061603
SB2022061612
and 23 more
#VU63698 - Incorrect Regular Expression
CVE-2021-33502
CWE-185 Medium
No
No
2.2.9 26.05.2022 SB2021052416
SB2022052615
SB2022060618
and 17 more
#VU59234 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-22960
CWE-444 Medium
No
No
2.2.9 05.01.2022 SB2022010523
SB2022010524
SB2022042806
and 40 more
#VU59233 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-22959
CWE-444 Medium
No
No
2.2.9 05.01.2022 SB2022010523
SB2022010524
SB2022011841
and 43 more
#VU58206 - Absolute Path Traversal
CVE-2021-32803
CWE-36 Medium
No
No
2.2.9 17.11.2021 SB2021080329
SB2022031104
SB2022060618
and 26 more
#VU58204 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37713
CWE-22 Medium
No
No
2.2.9 17.11.2021 SB2021111707
SB2022031104
SB2022060618
and 13 more
#VU58202 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37701
CWE-22 Medium
No
No
2.2.9 17.11.2021 SB2021111706
SB2021111710
SB2022031104
and 24 more
#VU53202 - Command injection
CVE-2021-23337
CWE-77 Medium
No
No
2.2.9 12.05.2021 SB2021021525
SB2021051230
SB2021062703
and 59 more
#VU41989 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-8203
CWE-94 Medium
No
No
2.2.9 10.08.2020 SB2020071548
SB2020122111
SB2021042308
and 31 more
#VU27519 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11023
CWE-79 Low
Available
Exploited
2.2.9 05.05.2020 SB2020042126
SB2020052033
SB2020052103
and 180 more
#VU27052 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11022
CWE-79 Low
Available
No
2.2.9 21.04.2020 SB2020042126
SB2020052033
SB2020052103
and 181 more
#VU21764 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-10744
CWE-94 Medium
No
No
2.2.9 14.10.2019 SB2019072612
SB2021012219
SB2022061803
and 14 more
#VU19305 - Improper Control of Generation of Code ('Code Injection')
CVE-2018-16487
CWE-94 High
No
No
2.2.9 22.07.2019 SB2019020111
SB2022062806
SB2022101801
and 13 more
#VU19282 - Resource exhaustion
CVE-2019-1010266
CWE-400 Medium
No
No
2.2.9 22.07.2019 SB2019020111
SB2022062806
SB2022101801
and 8 more
#VU18092 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2019-11358
CWE-1321 Low
Available
No
2.2.9 28.03.2019 SB2019032804
SB2019041026
SB2019041801
and 155 more
#VU37072 - Improper input validation
CVE-2018-3721
CWE-20 Medium
No
No
2.2.9 07.06.2018 SB2018060730
SB2022062806
SB2022101801
and 7 more


Showing elements 21 - 40 out of 47