CVE-2024-22347
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could all
CVSS
5.9
Medio
EPSS
0.3%
p25
KEV
—
Exploit Today
8
0-100
Publicado: 20 ene 2025 · Última mod.: 27 jul 2026 · CWE-327
0.3%EPSS · 30 días0.3%
2026-08-172026-09-13
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-174678.2 ALT—
———IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.15hCVE-2026-818228.4 ALT0.3%
——0The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.4dCVE-2026-693825.9 MED37.5%
——11Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.7dCVE-2026-166934.4 MED3.0%
——1IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.7dCVE-2026-818596.2 MED1.4%
——0CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm.7dCVE-2026-761339.8 CRÍ33.2%
——10The affected Ebyte
product
uses a deprecated hashing algorithm in an authentication-related
operation. Under conditions where an attacker can manipulate or predict
the authentication exchange, the weak construction may reduce the
assurance provided by the authentication mechanism and facilitate
unauthorized access.14d