Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2016-10-05 CVE-2016-8343 Path Traversal vulnerability in Indasengineering web Scada
Directory traversal vulnerability in INDAS Web SCADA before 3 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
indasengineering CWE-22
7.5
2016-10-05 CVE-2016-6420 Information Exposure vulnerability in Cisco Firesight System Software
Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467.
network
low complexity
cisco CWE-200
6.5
2016-10-05 CVE-2016-6419 SQL Injection vulnerability in Cisco Secure Firewall Management Center
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.
network
high complexity
cisco CWE-89
7.5
2016-10-05 CVE-2016-5983 Improper Access Control vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.
network
high complexity
ibm CWE-284
7.5
2016-10-05 CVE-2016-5901 Cross-site Scripting vulnerability in IBM Business Process Manager
Cross-site scripting (XSS) vulnerability in a test page in IBM Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before cumulative fix 2016.09 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
ibm CWE-79
5.4
2016-10-05 CVE-2016-5892 Cross-site Scripting vulnerability in IBM products
Cross-site scripting (XSS) vulnerability in IBM 10x, as used in Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications before 1.0.0.5_2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
ibm CWE-79
5.4
2016-10-05 CVE-2016-5686 Improper Authentication vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol.
network
low complexity
animas CWE-287
critical
9.8
2016-10-05 CVE-2016-5086 Improper Authentication vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.
network
low complexity
animas CWE-287
critical
9.8
2016-10-05 CVE-2016-5085 Use of Insufficiently Random Values vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.
network
low complexity
animas CWE-330
7.5
2016-10-05 CVE-2016-5084 Cryptographic Issues vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
animas CWE-310
7.5