Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2017-02-01 CVE-2016-0218 Cross-site Scripting vulnerability in IBM Cognos Business Intelligence
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-0217 Cross-site Scripting vulnerability in IBM Cognos Analytics
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-8967 Credentials Management vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-255
5.5
2017-02-01 CVE-2016-6117 Information Exposure vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.
network
low complexity
ibm CWE-200
5.3
2017-02-01 CVE-2016-6105 Improper Access Control vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas.
network
low complexity
ibm CWE-284
8.2
2017-02-01 CVE-2016-0371 Unspecified vulnerability in IBM Tivoli Storage Manager
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.
local
low complexity
ibm
5.5
2017-02-01 CVE-2016-9731 Cross-site Scripting vulnerability in IBM Business Process Manager 8.5.7.0
IBM Business Process Manager is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-8981 Information Exposure vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-200
5.5
2017-02-01 CVE-2016-8980 XXE vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data.
network
low complexity
ibm CWE-611
8.1
2017-02-01 CVE-2016-8966 Information Exposure vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-200
5.9