VendorsIBMsmartcloud_analytics_log_analysisall versions
Vulnerabilities

IBM Smartcloud Analytics Log Analysis

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2019-4244
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-Force ID: 159518.
Published 2019-12-10 · Modified
9.1EPSS 0.021
CVE-2024-40682
IBM SmartCloud Analytics - Log Analysis denial of service
Published 2025-07-23 · Analyzed
6.2EPSS 0.001
CVE-2019-4215
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 159186.
Published 2019-11-22 · Modified
6.1EPSS 0.009
CVE-2024-40686
IBM SmartCloud Analytics - Log Analysis HOST header injection
Published 2025-07-23 · Analyzed
6.1EPSS 0.002
CVE-2024-41750
IBM SmartCloud Analytics - Log Analysis security bypass
Published 2025-07-23 · Analyzed
5.5EPSS 0.001
CVE-2024-41751
IBM SmartCloud Analytics - Log Analysis security bypass
Published 2025-07-23 · Analyzed
5.5EPSS 0.001
CVE-2019-4243
IBM SmartCloud Analytics 1.3.1 through 1.3.5 allows unauthorized disclosure of information like accessing solrconfig.xml and could allow an attacker to perform disruptive administrator tasks. IBM X-Force ID: 159517.
Published 2019-11-22 · Modified
5.1EPSS 0.003
CVE-2019-4216
IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM X-Force ID: 159187.
Published 2019-11-22 · Modified
4.9EPSS 0.006
CVE-2013-6738
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.
Published 2014-04-24 · Modified
4.3EPSS 0.021
CVE-2019-4214
IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159185.
Published 2019-11-22 · Modified
4.3EPSS 0.005