Latest CVE Feed
-
5.5
MEDIUMCVE-2016-8963
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8930
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8929
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8928
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-6115
IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2016-6001
IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.... Read more
Affected Products : forms_experience_builder- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-2942
IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processes to run on a remote UCD agent machine.... Read more
Affected Products : urbancode_deploy- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-6117
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.... Read more
Affected Products : security_key_lifecycle_manager- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2016-6105
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas.... Read more
Affected Products : security_key_lifecycle_manager- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-0371
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8921
IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.... Read more
Affected Products : filenet_workplace_xt- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-8911
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click... Read more
Affected Products : kenexa_lms_on_cloud- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9418
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive information from ACP backups via vectors involving a short name.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6090
IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performing of unauthorized administrative operations, and potentially causing a denial of service.... Read more
Affected Products : websphere_commerce- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6065
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.... Read more
Affected Products : security_guardium- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6061
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
Affected Products : rational_collaborative_lifecycle_management- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6039
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
Affected Products : jazz_reporting_service- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-5950
IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user.... Read more
Affected Products : kenexa_lcms_premier- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-5937
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.... Read more
Affected Products : kenexa_lcms_premier- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2016-3046
IBM Security Access Manager for Web is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements which could allow the attacker to view information in the back-end database.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025