Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-02-01 CVE-2016-3045 Information Exposure vulnerability in IBM products
IBM Security Access Manager for Web stores sensitive information in URL parameters.
network
high complexity
ibm CWE-200
3.7
2017-02-01 CVE-2016-3043 Information Exposure vulnerability in IBM products
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-200
5.9
2017-02-01 CVE-2016-3035 Information Exposure vulnerability in IBM Security Appscan Source 9.0.1/9.0.2/9.0.3
IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.
network
low complexity
ibm CWE-200
5.3
2017-02-01 CVE-2016-3024 Information Exposure vulnerability in IBM products
IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-200
4.0
2017-02-01 CVE-2016-3023 Information Exposure vulnerability in IBM products
IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.
network
low complexity
ibm CWE-200
5.3
2017-02-01 CVE-2016-3021 Information Exposure vulnerability in IBM products
IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.
network
low complexity
ibm CWE-200
2.7
2017-02-01 CVE-2016-2987 Information Exposure vulnerability in IBM products
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker.
network
low complexity
ibm CWE-200
4.3
2017-02-01 CVE-2016-0297 Information Exposure vulnerability in IBM Bigfix Platform
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques.
network
high complexity
ibm CWE-200
3.7
2017-01-31 CVE-2016-9418 Information Exposure vulnerability in Mybb Merge System and Mybb
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive information from ACP backups via vectors involving a short name.
network
low complexity
mybb CWE-200
7.5
2017-01-31 CVE-2016-9414 Information Exposure vulnerability in Mybb
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveraging missing directory listing protection in upload directories.
network
low complexity
mybb CWE-200
7.5