Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2017-02-01 CVE-2016-6085 Improper Access Control vulnerability in IBM Bigfix Platform
IBM BigFix Platform could allow an attacker on the local network to crash the BES and relay servers.
low complexity
ibm CWE-284
6.5
2017-02-01 CVE-2016-6084 Improper Input Validation vulnerability in IBM Bigfix Platform 9.0/9.1
IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request.
low complexity
ibm CWE-20
6.5
2017-02-01 CVE-2016-6082 Use After Free vulnerability in IBM Bigfix Platform
IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition.
network
low complexity
ibm CWE-416
critical
10.0
2017-02-01 CVE-2016-6080 Information Exposure vulnerability in IBM Websphere Message Broker 8.0
The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.
network
low complexity
ibm CWE-200
5.3
2017-02-01 CVE-2016-6072 Cross-site Scripting vulnerability in IBM products
IBM Maximo Asset Management is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-6065 OS Command Injection vulnerability in IBM Security Guardium
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.
local
low complexity
ibm CWE-78
7.8
2017-02-01 CVE-2016-6061 Cross-site Scripting vulnerability in IBM Rational Collaborative Lifecycle Management
IBM Jazz Foundation is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-6059 XXE vulnerability in IBM products
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data.
network
low complexity
ibm CWE-611
8.1
2017-02-01 CVE-2016-6054 Cross-site Scripting vulnerability in IBM Jazz Reporting Service
IBM Jazz Foundation is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-6047 Cross-site Scripting vulnerability in IBM Jazz Reporting Service 6.0.2
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4