Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2017-12-07 CVE-2017-1341 Unspecified vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 and 9.0 could allow, under special circumstances, an unauthorized user to access an object which they should have been denied access.
network
high complexity
ibm
3.7
2017-12-07 CVE-2017-1336 Code Injection vulnerability in IBM Infosphere Biginsights 4.2.0
IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files.
network
high complexity
ibm CWE-94
4.4
2017-12-07 CVE-2017-1271 Inadequate Encryption Strength vulnerability in IBM Security Guardium 9.0/9.1/9.5
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
network
low complexity
ibm CWE-326
7.5
2017-11-27 CVE-2017-1689 Cross-site Scripting vulnerability in IBM Rational Doors Next Generation
IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-11-27 CVE-2017-1688 Cross-site Scripting vulnerability in IBM Rational Doors Next Generation
IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-11-27 CVE-2017-1678 Cross-site Scripting vulnerability in IBM Rational Doors Next Generation
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-11-27 CVE-2017-1650 Cross-site Scripting vulnerability in IBM Rational Doors Next Generation
IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-11-27 CVE-2017-1628 Incorrect Authorization vulnerability in IBM Business Process Manager 8.6.0.0
IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorization checks.
network
low complexity
ibm CWE-863
6.5
2017-11-27 CVE-2017-1607 Cross-site Scripting vulnerability in IBM Rational Doors Next Generation
IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-11-27 CVE-2017-1593 Cross-site Scripting vulnerability in IBM Rational Doors Next Generation
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4