Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2018-02-21 CVE-2016-0369 XXE vulnerability in IBM Forms Experience Builder 8.5/8.5.1/8.6.0
XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data.
network
low complexity
ibm CWE-611
2.7
2018-02-21 CVE-2016-0367 Information Exposure vulnerability in IBM Security Identity Manager Virtual Appliance
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message.
network
low complexity
ibm CWE-200
4.3
2018-02-21 CVE-2016-0366 Information Exposure vulnerability in IBM Security Privileged Identity Manager 2.0
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption.
network
high complexity
ibm CWE-200
3.7
2018-02-21 CVE-2016-0351 Information Exposure vulnerability in IBM Security Identity Manager Virtual Appliance
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
network
high complexity
ibm CWE-200
3.7
2018-02-21 CVE-2016-0348 Cross-Site Request Forgery (CSRF) vulnerability in IBM Tririga Application Platform
Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
network
low complexity
ibm CWE-352
8.0
2018-02-21 CVE-2016-0345 Information Exposure vulnerability in IBM Tririga Application Platform
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering.
network
low complexity
ibm CWE-200
4.3
2018-02-21 CVE-2016-0344 Cross-site Scripting vulnerability in IBM Tririga Application Platform
Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
ibm CWE-79
5.4
2018-02-21 CVE-2016-0343 Information Exposure vulnerability in IBM Tririga Application Platform
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain sensitive information by reading an error message.
network
low complexity
ibm CWE-200
4.3
2018-02-19 CVE-2018-1411 Unspecified vulnerability in IBM Client Application Access and Notes
IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system.
local
low complexity
ibm
7.8
2018-02-19 CVE-2018-1410 Unspecified vulnerability in IBM Client Application Access and Notes
IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system.
local
low complexity
ibm
7.8