Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-03-28 CVE-2016-9121 Inadequate Encryption Strength vulnerability in Go-Jose Project Go-Jose
go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm.
network
low complexity
go-jose-project CWE-326
critical
9.1
2017-03-28 CVE-2017-6964 Unchecked Return Value vulnerability in multiple products
dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended to run as an unprivileged user, as root.
local
low complexity
canonical debian CWE-252
7.8
2017-03-27 CVE-2017-1153 Unspecified vulnerability in IBM Tririga Application Platform
IBM TRIRIGA Report Manager 3.2 through 3.5 contains a vulnerability that could allow an authenticated user to execute actions that they do not have access to.
network
low complexity
ibm
8.8
2017-03-27 CVE-2017-1143 Information Exposure vulnerability in IBM Kenexa Lcms Premier
IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-200
5.3
2017-03-27 CVE-2017-1142 Information Exposure vulnerability in IBM Kenexa Lcms Premier
IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode.
network
low complexity
ibm CWE-200
6.5
2017-03-27 CVE-2017-1120 Cross-site Scripting vulnerability in IBM Websphere Portal 8.5/9.0
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-03-27 CVE-2016-9737 Cross-site Scripting vulnerability in IBM Tririga Application Platform
IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-03-27 CVE-2016-8960 Permissions, Privileges, and Access Controls vulnerability in IBM Cognos Business Intelligence
IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privilege user's cookie value from its HTTP request and then reusing it in subsequent requests.
network
low complexity
ibm CWE-264
8.8
2017-03-27 CVE-2016-6102 Information Exposure vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters.
network
high complexity
ibm CWE-200
3.7
2017-03-27 CVE-2016-6056 Cross-site Scripting vulnerability in IBM Call Center for Commerce 9.3/9.4
IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4