Latest CVE Feed
-
5.4
MEDIUMCVE-2017-1424
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus... Read more
Affected Products : business_process_manager- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1425
IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more
Affected Products : business_process_manager- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1429
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : rational_engineering_lifecycle_manager- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1441
IBM Emptoris Services Procurement 10.0.0.5 could allow a local user to view sensitive information stored locally due to improper access control. IBM X-Force ID: 128106.... Read more
Affected Products : emptoris_services_procurement- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1447
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus... Read more
Affected Products : emptoris_sourcing- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1433
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow an authenticated user to insert messages with a corrupt RFH header into the channel which would cause it to restart. IBM X-Force ID: 127803.... Read more
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1446
IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
Affected Products : emptoris_spend_analysis- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1465
IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and... Read more
Affected Products : tririga_application_platform- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-1453
IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the ... Read more
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1570
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 131852.... Read more
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-1451
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178.... Read more
- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1443
IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more
Affected Products : emptoris_services_procurement- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1457
IBM QRadar Network Security 5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted... Read more
Affected Products : qradar_network_security- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-1469
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.... Read more
Affected Products : infosphere_information_server- Published: Aug. 14, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-1477
IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force... Read more
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1498
IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IB... Read more
Affected Products : connections- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2014-9940
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.... Read more
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1482
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure... Read more
Affected Products : sterling_b2b_integrator- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1548
IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 131288.... Read more
Affected Products : sterling_file_gateway- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1487
IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on the system. IBM X-Force ID: 128626.... Read more
Affected Products : sterling_file_gateway- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025