I2 Analysts Notebook
Vendor:
First CVE: May 14, 2020 · Active for 6 years
29
Total CVEs
More Total CVEs than 97% of tracked products
14.5
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 64% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact I2 Analysts Notebook over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 14, 2020
6 years ago
Most Recent CVE
Dec 13, 2021
1,688 days ago
CVE Severity & Scoring
I2 Analysts Notebook29 CVEs
93%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local27 (93.1%)
Network2 (6.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (10.3%)
Unknown0 (0.0%)
Required26 (89.7%)
Privileges Required
Low3 (10.3%)
High0 (0.0%)
None26 (89.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-4422HIGH IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a spe | May 14, 2020 | 7.8 | 26 | NO | NO |
CVE-2020-4343HIGH IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a spe | May 14, 2020 | 7.8 | 26 | NO | NO |
CVE-2020-4285HIGH IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error. By persuading a victim to open | May 14, 2020 | 7.8 | 26 | NO | NO |
CVE-2021-39050HIGH IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and g | Dec 13, 2021 | 7.8 | 25 | NO | NO |
CVE-2020-4723HIGH IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specia | Oct 29, 2020 | 7.8 | 25 | NO | NO |
CVE-2021-39049HIGH IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and g | Dec 13, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-4722HIGH IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specia | Oct 29, 2020 | 7.8 | 24 | NO | NO |
CVE-2020-4264HIGH IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a spec | May 14, 2020 | 7.8 | 24 | NO | NO |
CVE-2020-4263HIGH IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a spec | May 14, 2020 | 7.8 | 24 | NO | NO |
CVE-2020-4261HIGH IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a spec | May 14, 2020 | 7.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (29 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (29 CVEs).
Media Mentions
Signals from CVEs in this product scope (29 CVEs).
Top CNAs Publishing CVEs For I2 Analysts Notebook
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.2.2 | 6 | 7.4 | 0.6% | 0 | 0 |
| 9.2.1 | 27 | 7.7 | 1.2% | 0 | 0 |
| 9.2.0 | 6 | 7.2 | 1.4% | 0 | 0 |