Vulnerabilities > IBM > Connections > 5.5

DATE CVE VULNERABILITY TITLE RISK
2018-12-07 CVE-2018-1896 Injection vulnerability in IBM Connections 5.0/5.5/6.0
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain.
network
low complexity
ibm CWE-74
5.4
2018-12-06 CVE-2018-1935 Information Exposure vulnerability in IBM Connections 5.0/5.5/6.0
IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request error messages.
network
low complexity
ibm CWE-200
4.3
2018-09-14 CVE-2018-1791 Improper Input Validation vulnerability in IBM Connections 5.0/5.5/6.0
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation of a request property.
network
high complexity
ibm CWE-20
4.9
2018-02-14 CVE-2017-1682 Cross-site Scripting vulnerability in IBM Connections
IBM Connections 4.0, 4.5, 5.0, 5.5, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2016-09-26 CVE-2016-2999 Information Exposure vulnerability in IBM Connections
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.
network
low complexity
ibm CWE-200
6.5