Vulnerabilities > IBM
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-02-01 | CVE-2016-6085 | Improper Access Control vulnerability in IBM Bigfix Platform IBM BigFix Platform could allow an attacker on the local network to crash the BES and relay servers. | 6.5 |
2017-02-01 | CVE-2016-6084 | Improper Input Validation vulnerability in IBM Bigfix Platform 9.0/9.1 IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request. | 6.5 |
2017-02-01 | CVE-2016-6082 | Use After Free vulnerability in IBM Bigfix Platform IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. | 10.0 |
2017-02-01 | CVE-2016-6080 | Information Exposure vulnerability in IBM Websphere Message Broker 8.0 The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker. | 5.3 |
2017-02-01 | CVE-2016-6072 | Cross-site Scripting vulnerability in IBM products IBM Maximo Asset Management is vulnerable to cross-site scripting. | 5.4 |
2017-02-01 | CVE-2016-6065 | OS Command Injection vulnerability in IBM Security Guardium IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root. | 7.8 |
2017-02-01 | CVE-2016-6061 | Cross-site Scripting vulnerability in IBM Rational Collaborative Lifecycle Management IBM Jazz Foundation is vulnerable to cross-site scripting. | 5.4 |
2017-02-01 | CVE-2016-6059 | XXE vulnerability in IBM products IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. | 8.1 |
2017-02-01 | CVE-2016-6054 | Cross-site Scripting vulnerability in IBM Jazz Reporting Service IBM Jazz Foundation is vulnerable to cross-site scripting. | 5.4 |
2017-02-01 | CVE-2016-6047 | Cross-site Scripting vulnerability in IBM Jazz Reporting Service 6.0.2 IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. | 5.4 |