Vulnerabilities > IBM > Connections > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-11-30 CVE-2016-2957 Information Exposure vulnerability in IBM Connections 4.0.0.0/4.5.0.0/5.0.0.0
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.
network
low complexity
ibm CWE-200
4.3
2016-09-26 CVE-2016-3006 Cross-site Scripting vulnerability in IBM Connections
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-3001 and CVE-2016-3003.
network
low complexity
ibm CWE-79
5.4
2016-09-26 CVE-2016-3003 Cross-site Scripting vulnerability in IBM Connections
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-3001 and CVE-2016-3006.
network
low complexity
ibm CWE-79
5.4
2016-09-26 CVE-2016-3001 Cross-site Scripting vulnerability in IBM Connections
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-3003 and CVE-2016-3006.
network
low complexity
ibm CWE-79
5.4
2016-09-26 CVE-2016-3000 Improper Input Validation vulnerability in IBM Connections
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.
network
low complexity
ibm CWE-20
4.3
2016-09-26 CVE-2016-2999 Information Exposure vulnerability in IBM Connections
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.
network
low complexity
ibm CWE-200
6.5
2016-09-01 CVE-2016-3010 Cross-site Scripting vulnerability in IBM Connections
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-2997, and CVE-2016-3005.
network
low complexity
ibm CWE-79
5.4
2016-09-01 CVE-2016-3008 Cross-site Scripting vulnerability in IBM Connections 5.0.0.0/5.5.0.0
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2954 and CVE-2016-2956.
network
low complexity
ibm CWE-79
5.4
2016-09-01 CVE-2016-3005 Cross-site Scripting vulnerability in IBM Connections
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-2997, and CVE-2016-3010.
network
low complexity
ibm CWE-79
5.4
2016-09-01 CVE-2016-2997 Cross-site Scripting vulnerability in IBM Connections
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-3005, and CVE-2016-3010.
network
low complexity
ibm CWE-79
5.4