Vulnerabilities > IBM > Daeja Viewone > 4.1.5

DATE CVE VULNERABILITY TITLE RISK
2018-02-27 CVE-2018-1399 Cross-site Scripting vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5 and 5.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-10-24 CVE-2017-1212 Unspecified vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of service when viewing or opening a large file.
network
low complexity
ibm
6.5
2017-10-24 CVE-2017-1211 Information Exposure vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled.
local
high complexity
ibm CWE-200
2.5
2017-10-24 CVE-2017-1210 Improper Input Validation vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to look legitimate.
network
low complexity
ibm CWE-20
7.5
2017-10-24 CVE-2017-1209 Cross-site Scripting vulnerability in IBM Daeja Viewone
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-07-13 CVE-2017-1308 Files or Directories Accessible to External Parties vulnerability in IBM Daeja Viewone 4.1.5/4.1.5.1/5.0
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls.
network
low complexity
ibm CWE-552
6.5