Vulnerabilities > IBM > Infosphere Biginsights > 2.0.0.0

DATE CVE VULNERABILITY TITLE RISK
2014-08-17 CVE-2014-0905 Permissions, Privileges, and Access Controls vulnerability in IBM Infosphere Biginsights
IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
2.9
2014-07-07 CVE-2013-3993 Permissions, Privileges, and Access Controls vulnerability in IBM Infosphere Biginsights
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.
network
ibm CWE-264
3.5
2014-03-26 CVE-2013-3998 Code Injection vulnerability in IBM Infosphere Biginsights
CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
network
ibm CWE-94
3.5
2014-03-26 CVE-2013-3997 Improper Input Validation vulnerability in IBM Infosphere Biginsights
Open redirect vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
ibm CWE-20
4.9
2013-08-06 CVE-2013-3996 Improper Input Validation vulnerability in IBM Infosphere Biginsights
IBM InfoSphere BigInsights 1.1 through 2.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site.
network
ibm CWE-20
4.9
2013-08-06 CVE-2013-3995 Cross-Site Scripting vulnerability in IBM Infosphere Biginsights
Cross-site scripting (XSS) vulnerability in IBM InfoSphere BigInsights 1.1 through 2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
3.5
2013-08-06 CVE-2013-3992 Cross-Site Request Forgery (CSRF) vulnerability in IBM Infosphere Biginsights 2.0.0.0/2.1.0.0
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere BigInsights 2.0 through 2.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
network
ibm CWE-352
6.0