Vulnerabilities > IBM > Infosphere Biginsights > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-04-20 | CVE-2014-4782 | Information Exposure vulnerability in IBM Infosphere Biginsights 2.1.2 IBM InfoSphere BigInsights 2.1.2 allows remote authenticated users to discover SMTP server credentials via vectors related to the Alert management service. | 6.5 |
2017-12-07 | CVE-2017-1336 | Code Injection vulnerability in IBM Infosphere Biginsights 4.2.0 IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. | 4.4 |
2017-11-01 | CVE-2017-1554 | Cross-site Scripting vulnerability in IBM Infosphere Biginsights 4.2.0/4.2.5 IBM Infosphere BigInsights 4.2.0 and 4.2.5 could allow a remote attacker to hijack the clicking action of the victim. | 5.4 |
2017-11-01 | CVE-2017-1553 | Cross-site Scripting vulnerability in IBM Infosphere Biginsights 4.2.0/4.2.5 IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to cross-site scripting. | 5.4 |
2017-11-01 | CVE-2017-1552 | Cross-site Scripting vulnerability in IBM Infosphere Biginsights 4.2.0/4.2.5 IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. | 5.4 |
2016-01-02 | CVE-2015-5020 | Permissions, Privileges, and Access Controls vulnerability in IBM Infosphere Biginsights The Big SQL component in IBM InfoSphere BigInsights 3.0, 3.0.0.1, 3.0.0.2, and 4.0 allows remote authenticated users to bypass intended access restrictions and truncate arbitrary tables via unspecified vectors. | 4.3 |
2014-07-07 | CVE-2013-3993 | Path Traversal vulnerability in IBM Infosphere Biginsights IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls. | 6.5 |