Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2017-07-31 CVE-2017-1496 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-07-31 CVE-2017-1460 Improper Input Validation vulnerability in IBM I
IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin.
network
low complexity
ibm CWE-20
7.5
2017-07-31 CVE-2017-1386 Weak Password Requirements vulnerability in IBM API Connect and API Management
IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques.
network
high complexity
ibm CWE-521
5.9
2017-07-31 CVE-2017-1370 Information Exposure Through an Error Message vulnerability in IBM Jazz Reporting Service
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page.
network
low complexity
ibm CWE-209
4.9
2017-07-31 CVE-2017-1332 Cross-site Scripting vulnerability in IBM Inotes
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-07-31 CVE-2017-1303 Cross-site Scripting vulnerability in IBM Websphere Portal
IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-07-31 CVE-2017-1227 Allocation of Resources Without Limits or Throttling vulnerability in IBM Bigfix Platform 9.1/9.2/9.5
IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system.
network
low complexity
ibm CWE-770
7.5
2017-07-31 CVE-2016-9719 Improper Input Validation vulnerability in IBM Infosphere Master Data Management Server
IBM InfoSphere Master Data Management Server 10.1.
network
low complexity
ibm CWE-20
5.7
2017-07-31 CVE-2016-9718 Cross-site Scripting vulnerability in IBM Infosphere Master Data Management Server
IBM InfoSphere Master Data Management Server 10.1.
network
low complexity
ibm CWE-79
5.4
2017-07-31 CVE-2016-9717 Improper Input Validation vulnerability in IBM Infosphere Master Data Management Server
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1.
network
low complexity
ibm CWE-20
6.5