Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2017-11-13 CVE-2017-1453 OS Command Injection vulnerability in IBM Security Access Manager 9.0 Firmware 9.0.3.0
IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system.
network
low complexity
ibm CWE-78
8.8
2017-11-13 CVE-2017-1229 Information Exposure vulnerability in IBM Bigfix Platform 9.2/9.5
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-200
5.9
2017-11-13 CVE-2017-1221 Weak Password Requirements vulnerability in IBM Bigfix Platform 9.2/9.5
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2017-11-01 CVE-2017-1554 Cross-site Scripting vulnerability in IBM Infosphere Biginsights 4.2.0/4.2.5
IBM Infosphere BigInsights 4.2.0 and 4.2.5 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-79
5.4
2017-11-01 CVE-2017-1553 Cross-site Scripting vulnerability in IBM Infosphere Biginsights 4.2.0/4.2.5
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-11-01 CVE-2017-1552 Cross-site Scripting vulnerability in IBM Infosphere Biginsights 4.2.0/4.2.5
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection.
network
low complexity
ibm CWE-79
5.4
2017-11-01 CVE-2017-1340 Information Exposure vulnerability in IBM Jazz Reporting Service 6.0.4
IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with.
network
low complexity
ibm CWE-200
5.0
2017-11-01 CVE-2017-1333 Information Exposure vulnerability in IBM Openpages GRC Platform
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used in future attacks against the system.
network
low complexity
ibm CWE-200
5.3
2017-11-01 CVE-2017-1300 Cross-Site Request Forgery (CSRF) vulnerability in IBM Openpages GRC Platform
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2017-11-01 CVE-2017-1290 Cross-site Scripting vulnerability in IBM Openpages GRC Platform
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4