Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-03-20 CVE-2017-1155 Information Exposure vulnerability in IBM Algo ONE 4.9.1/5.0.0/5.1.0
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to another user's reports using a specially crafted HTTP request.
network
low complexity
ibm CWE-200
4.3
2017-03-20 CVE-2016-9697 Information Exposure vulnerability in IBM Rational Rhapsody Design Manager
An unspecified vulnerability in IBM Rhapsody DM 4.0, 5.0, and 6.0 could allow an attacker to perform a JSON Hijacking Attack.
network
high complexity
ibm CWE-200
3.1
2017-03-20 CVE-2016-9165 Information Exposure vulnerability in CA products
The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain active session ids and consequently bypass authentication or gain privileges via unspecified vectors.
network
low complexity
ca CWE-200
7.5
2017-03-20 CVE-2016-2981 Information Exposure vulnerability in IBM Rational Collaborative Lifecycle Management
An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials.
low complexity
ibm CWE-200
6.8
2017-03-17 CVE-2017-3871 Information Exposure vulnerability in Cisco Prime Optical 10.6(0.1)
A RADIUS Secret Disclosure vulnerability in the web network management interface of Cisco Prime Optical for Service Providers could allow an authenticated, remote attacker to disclose sensitive information in the configuration generated for a device.
network
low complexity
cisco CWE-200
4.3
2017-03-17 CVE-2015-3882 Information Exposure vulnerability in Qdpm 8.3
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation path in an error message.
network
low complexity
qdpm CWE-200
5.3
2017-03-17 CVE-2015-3881 Information Exposure vulnerability in Qdpm 8.3
Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.yml, (2) core/log/qdPM_prod.log, or (3) core/apps/qdPM/config/settings.yml.
network
low complexity
qdpm CWE-200
7.5
2017-03-17 CVE-2014-8723 Information Exposure vulnerability in Get-Simple Getsimple CMS 3.3.4
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message.
network
low complexity
get-simple CWE-200
5.3
2017-03-17 CVE-2014-8722 Information Exposure vulnerability in Get-Simple Getsimple CMS 3.3.4
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.xml, or (4) data/other/appid.xml.
network
low complexity
get-simple CWE-200
7.5
2017-03-17 CVE-2014-8706 Information Exposure vulnerability in Pluck-Cms Pluck 4.7.2
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the installation path in an error message.
network
low complexity
pluck-cms CWE-200
5.3