Vulnerabilities > IBM > Lotus Protector FOR Mail Security > 2.8

DATE CVE VULNERABILITY TITLE RISK
2016-12-01 CVE-2016-2991 Cross-site Scripting vulnerability in IBM Lotus Protector for Mail Security 2.8/2.8.1
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 through 2.8.1.0 before 2.8.1.0-22115 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
3.5
2014-03-25 CVE-2014-0887 OS Command Injection vulnerability in IBM Lotus Protector for Mail Security 2.8/2.8.1
The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.
network
high complexity
ibm CWE-78
7.1
2014-03-25 CVE-2014-0886 OS Command Injection vulnerability in IBM Lotus Protector for Mail Security 2.8/2.8.1
The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors.
network
high complexity
ibm CWE-78
7.1
2014-03-25 CVE-2014-0885 Cross-Site Request Forgery (CSRF) vulnerability in IBM Lotus Protector for Mail Security 2.8/2.8.1
Cross-site request forgery (CSRF) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
network
ibm CWE-352
6.8
2014-03-25 CVE-2014-0884 Cross-Site Scripting vulnerability in IBM Lotus Protector for Mail Security 2.8/2.8.1
Cross-site scripting (XSS) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
3.5
2012-07-27 CVE-2012-2202 Path Traversal vulnerability in IBM products
Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a ..
network
ibm CWE-22
3.5
2012-07-20 CVE-2012-2955 Cross-Site Scripting vulnerability in IBM products
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string.
network
ibm CWE-79
4.3