Filtered by vendor Ibm
Subscribe
Total
6536 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2012-2202 | 1 Ibm | 3 Lotus Protector For Mail Security, Proventia Network Mail Security System, Proventia Network Mail Security System Firmware | 2017-12-21 | 3.5 LOW | N/A |
Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the template parameter. | |||||
CVE-2012-2194 | 1 Ibm | 1 Db2 | 2017-12-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to replace JAR files via unspecified vectors. | |||||
CVE-2012-2955 | 1 Ibm | 3 Lotus Protector For Mail Security, Proventia Network Mail Security System, Proventia Network Mail Security System Firmware | 2017-12-21 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string. | |||||
CVE-2017-1549 | 1 Ibm | 1 Sterling File Gateway | 2017-12-20 | 3.5 LOW | 5.4 MEDIUM |
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131289. | |||||
CVE-2017-1548 | 1 Ibm | 1 Sterling File Gateway | 2017-12-20 | 5.0 MEDIUM | 5.3 MEDIUM |
IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 131288. | |||||
CVE-2017-1482 | 1 Ibm | 1 Sterling B2b Integrator | 2017-12-19 | 3.5 LOW | 5.4 MEDIUM |
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128620. | |||||
CVE-2017-1481 | 1 Ibm | 1 Sterling B2b Integrator | 2017-12-19 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619. | |||||
CVE-2017-1465 | 1 Ibm | 1 Tririga Application Platform | 2017-12-19 | 3.5 LOW | 5.4 MEDIUM |
IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 128464. | |||||
CVE-2017-1498 | 1 Ibm | 1 Connections | 2017-12-19 | 3.5 LOW | 5.4 MEDIUM |
IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129020. | |||||
CVE-2017-1271 | 1 Ibm | 1 Security Guardium | 2017-12-19 | 5.0 MEDIUM | 7.5 HIGH |
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 124746. | |||||
CVE-2017-1342 | 1 Ibm | 1 Insights Foundation For Energy | 2017-12-19 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Insights Foundation for Energy 2.0 could reveal sensitive information in error messages to authenticated users that could e used to conduct further attacks. IBM X-Force ID: 126457. | |||||
CVE-2017-1353 | 1 Ibm | 1 Atlas Ediscovery Process Management | 2017-12-19 | 3.5 LOW | 3.5 LOW |
IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when an unsuspecting user clicks on unsafe third-party links. IBM X-Force ID: 126680. | |||||
CVE-2017-1354 | 1 Ibm | 1 Atlas Ediscovery Process Management | 2017-12-19 | 3.5 LOW | 5.4 MEDIUM |
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126681. | |||||
CVE-2017-1355 | 1 Ibm | 1 Atlas Ediscovery Process Management | 2017-12-19 | 4.3 MEDIUM | 3.7 LOW |
IBM Atlas eDiscovery Process Management 6.0.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126682. | |||||
CVE-2017-1356 | 1 Ibm | 1 Atlas Ediscovery Process Management | 2017-12-19 | 6.5 MEDIUM | 8.8 HIGH |
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126683. | |||||
CVE-2001-0052 | 1 Ibm | 1 Db2 Universal Database | 2017-12-18 | 2.1 LOW | N/A |
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query. | |||||
CVE-2001-0472 | 1 Ibm | 1 High Availability Cluster Multiprocessing | 2017-12-18 | 5.0 MEDIUM | N/A |
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request. | |||||
CVE-2001-0924 | 1 Ibm | 1 Informix Web Datablade | 2017-12-18 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter. | |||||
CVE-1999-1275 | 1 Ibm | 1 Lotus Cc Mail | 2017-12-18 | 4.6 MEDIUM | N/A |
Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges. | |||||
CVE-2001-1265 | 1 Ibm | 1 Alphaworks Tftp Server | 2017-12-18 | 7.5 HIGH | N/A |
Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack. |