Threats Tagged 'cwe-327'
View all threats tagged with 'cwe-327'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-327'
Click on any threat for detailed analysis and mitigation recommendations
0 IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption. Join the discussion | CVE Database V5 | 09/24/2026, 14:11:44 UTC Added: 09/24/2026, 14:18:29 UTC |
Imprivata Enterprise Access Management (EAM) versions 26.2.6 and below do not support rotation of the RSA key pair used to generate the appliance's X.509 certificate. This means the same key pair is used indefinitely, violating cryptographic best practices. If an attacker obtains the private key, they can impersonate the appliance to any trusted endpoint, intercepting authentication traffic and potentially decrypting past communications if perfect forward secrecy is not enforced. The vendor is aware but has not provided a fix or timeline. Until resolved, users should protect the private key and enforce perfect forward secrecy. Join the discussion | CERT/CC | 09/23/2026, 21:30:41 UTC Added: 09/23/2026, 18:30:10 UTC |
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors. Join the discussion | CVE Database V5 | 09/22/2026, 22:07:12 UTC Added: 09/22/2026, 22:18:14 UTC |
0 IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. Join the discussion | CVE Database V5 | 09/22/2026, 21:20:10 UTC Added: 09/22/2026, 21:33:26 UTC |
0 IBM Cognos Analytics versions 12.1.0 through 12.1.3 FP1 and 12.0.4 through 12.0.4 FP2 contain a vulnerability due to the use of a broken or risky cryptographic algorithm. This flaw could allow an attacker on a shared network to obtain sensitive information by exploiting insecure network communication. The vulnerability has a medium severity with a CVSS score of 5.9. No official patch or remediation details are provided in the available data. Join the discussion | CVE Database V5 | 09/18/2026, 15:40:41 UTC Added: 09/18/2026, 15:47:09 UTC |
0 IBM Cognos Analytics versions 12.0.4 and 12.1.0 contain a vulnerability due to failure to properly enable HTTP Strict Transport Security (HSTS). This weakness could allow a remote attacker to intercept sensitive information via man-in-the-middle techniques. The issue is classified under CWE-327 for use of a broken or risky cryptographic algorithm. The vulnerability has a medium severity with a CVSS score of 5.9. Join the discussion | CVE Database V5 | 09/18/2026, 14:29:49 UTC Added: 09/18/2026, 22:13:06 UTC |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. Join the discussion | CVE Database V5 | 09/17/2026, 10:49:27 UTC Added: 09/17/2026, 11:02:18 UTC |
0 Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. Join the discussion | CVE Database V5 | 09/16/2026, 15:00:12 UTC Added: 09/16/2026, 15:47:09 UTC |
0 An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed. Join the discussion | GCVE Database | 09/15/2026, 23:20:56 UTC Added: 09/16/2026, 03:06:19 UTC |
0 CVE-2026-15638 is a critical vulnerability in Delinea Secret Server (On-Prem) versions 10.5.1 through 12.1.3. It allows an unauthenticated user with access to the server to perform a padding oracle attack to decrypt or encrypt data using one of the server's cryptographic keys. The cryptographic key itself is not exposed by this vulnerability. Join the discussion | CVE Database V5 | 09/15/2026, 23:20:56 UTC Added: 09/16/2026, 01:17:16 UTC |
Showing 1 to 10 of 123 results