Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2018-03-27 CVE-2015-4987 Improper Authentication vulnerability in IBM Tealeaf Customer Experience
The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified vectors.
network
low complexity
ibm CWE-287
6.4
2018-03-27 CVE-2015-4954 Improper Certificate Validation vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attackers to conduct spoofing attacks via unspecified vectors.
network
ibm CWE-295
4.3
2018-03-26 CVE-2015-7434 Information Exposure vulnerability in IBM Capacity Management Analytics 2.1.0.0
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install machine.
local
low complexity
ibm CWE-200
2.1
2018-03-26 CVE-2015-7433 Information Exposure vulnerability in IBM Capacity Management Analytics 2.1.0.0
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install machine.
local
low complexity
ibm CWE-200
2.1
2018-03-26 CVE-2015-7432 Information Exposure vulnerability in IBM Capacity Management Analytics 2.1.0.0
IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt.
local
low complexity
ibm CWE-200
2.1
2018-03-26 CVE-2015-7424 Information Exposure vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access.
network
low complexity
ibm CWE-200
4.0
2018-03-26 CVE-2015-7423 Cross-site Scripting vulnerability in IBM Infosphere Master Data Management
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
3.5
2018-03-26 CVE-2015-7401 Information Exposure vulnerability in IBM Curam Social Program Management
IBM Curam Social Program Management 6.1.x before 6.1.1.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive document information by guessing the document id.
network
low complexity
ibm CWE-200
4.0
2018-03-26 CVE-2015-5045 Information Exposure vulnerability in IBM Rational License KEY Server
The Administration and Reporting tool in IBM Rational License Key Server (RLKS) before 8.1.4.9 iFix 04 allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
ibm CWE-200
2.1
2018-03-26 CVE-2015-5039 Cryptographic Issues vulnerability in IBM Rational Clearcase
The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information or modify network traffic via a crafted certificate.
network
ibm CWE-310
5.8