Filtered by vendor Ibm
Subscribe
Total
6536 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-2012 | 1 Ibm | 1 Websphere Mq | 2016-12-05 | 2.1 LOW | 4.0 MEDIUM |
The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 uses world-readable permissions for a cleartext file containing the SSL keystore password, which allows local users to obtain sensitive information by reading this file. | |||||
CVE-2016-5890 | 1 Ibm | 1 Sterling B2b Integrator | 2016-12-02 | 3.5 LOW | 5.3 MEDIUM |
IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors. | |||||
CVE-2016-2887 | 2 Ibm, Microsoft | 2 Ims Enterprise Suite, .net Framework | 2016-12-02 | 5.5 MEDIUM | 8.1 HIGH |
IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. | |||||
CVE-2016-2940 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 5.0 MEDIUM | 5.3 MEDIUM |
Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors. | |||||
CVE-2016-2943 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 1.9 LOW | 1.9 LOW |
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file. | |||||
CVE-2016-2944 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 5.0 MEDIUM | 9.8 CRITICAL |
IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. | |||||
CVE-2016-2948 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 4.6 MEDIUM | 7.8 HIGH |
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors. | |||||
CVE-2016-2949 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 2.1 LOW | 3.3 LOW |
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session. | |||||
CVE-2016-2950 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 4.0 MEDIUM | 6.5 MEDIUM |
SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2016-2951 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 4.3 MEDIUM | 3.7 LOW |
IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data. | |||||
CVE-2016-2952 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 4.3 MEDIUM | 3.7 LOW |
IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP. | |||||
CVE-2016-2963 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |||||
CVE-2016-0211 | 1 Ibm | 2 Db2, Db2 Connect | 2016-12-02 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message. | |||||
CVE-2016-0226 | 2 Ibm, Microsoft | 2 Informix Dynamic Server, Windows | 2016-12-02 | 6.9 MEDIUM | 7.8 HIGH |
The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file. | |||||
CVE-2016-0227 | 1 Ibm | 1 Business Process Manager | 2016-12-02 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |||||
CVE-2016-0283 | 1 Ibm | 1 Websphere Application Server | 2016-12-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |||||
CVE-2015-8524 | 1 Ibm | 1 Business Process Manager | 2016-12-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |||||
CVE-2015-7400 | 1 Ibm | 1 Mashups Center | 2016-12-02 | 6.8 MEDIUM | 7.7 HIGH |
The Lotus Mashups component in IBM Mashup Center 3.0.0.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |||||
CVE-2015-7411 | 1 Ibm | 1 Tivoli Monitoring | 2016-12-02 | 9.0 HIGH | 9.9 CRITICAL |
The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain privileges via unspecified vectors. | |||||
CVE-2015-7454 | 1 Ibm | 2 Business Process Manager, Websphere Process Server | 2016-12-02 | 4.0 MEDIUM | 4.3 MEDIUM |
Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors. |