Latest CVE Feed
-
6.8
MEDIUMCVE-2016-5972
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-5971
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declarati... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5970
Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5963
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authenticated users to execute arbitrary code via unspecified vectors.... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-5957
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive information by leveraging a weak algorithm.... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2016-5947
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.... Read more
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5946
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.... Read more
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-5945
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.... Read more
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-5944
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.... Read more
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-5943
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properties, via unspecified vectors.... Read more
Affected Products : spectrum_control- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-3040
IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-3007
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary users.... Read more
Affected Products : connections- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-3006
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability th... Read more
Affected Products : connections- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-3003
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability th... Read more
Affected Products : connections- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-3001
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability th... Read more
Affected Products : connections- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-3000
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.... Read more
Affected Products : connections- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-2999
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.... Read more
Affected Products : connections- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2016-0379
IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager rights.... Read more
Affected Products : websphere_mq- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0248
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.... Read more
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-7549
Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possib... Read more
Affected Products : chrome- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025