Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2017-02-01 CVE-2016-8961 Open Redirect vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.1
2017-02-01 CVE-2016-8943 Cross-site Scripting vulnerability in IBM products
IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-8942 Improper Access Control vulnerability in IBM products
IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.
network
high complexity
ibm CWE-284
3.1
2017-02-01 CVE-2016-8941 Cross-Site Request Forgery (CSRF) vulnerability in IBM products
IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2017-02-01 CVE-2016-8936 Cross-site Scripting vulnerability in IBM Social Rendering Templates for Digital Data Connector 1.0
IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-02-01 CVE-2016-8934 Cross-site Scripting vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-8922 Cross-site Scripting vulnerability in IBM products
Exphox WebRadar is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-02-01 CVE-2016-8921 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Filenet Workplace XT 1.1.5
IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
network
low complexity
ibm CWE-434
8.8
2017-02-01 CVE-2016-8920 Cross-site Scripting vulnerability in IBM Kenexa LMS on Cloud
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-8918 Credentials Management vulnerability in IBM Integration BUS 10.0
IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid credentials.
network
high complexity
ibm CWE-255
5.9