Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2017-03-20 CVE-2016-9696 Cross-site Scripting vulnerability in IBM Rational Rhapsody Design Manager
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to HTML injection.
network
low complexity
ibm CWE-79
5.4
2017-03-20 CVE-2016-9694 Cross-site Scripting vulnerability in IBM Rational Rhapsody Design Manager
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-03-20 CVE-2016-8973 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Rational Rhapsody Design Manager
IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server.
network
low complexity
ibm CWE-434
4.3
2017-03-20 CVE-2016-2981 Information Exposure vulnerability in IBM Rational Collaborative Lifecycle Management
An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials.
low complexity
ibm CWE-200
6.8
2017-03-11 CVE-2017-5638 Improper Handling of Exceptional Conditions vulnerability in multiple products
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
network
low complexity
apache ibm lenovo hp oracle arubanetworks netapp CWE-755
critical
9.8
2017-03-08 CVE-2017-1150 Improper Privilege Management vulnerability in IBM DB2 10.1/10.5/11.1
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view.
network
high complexity
ibm CWE-269
3.1
2017-03-08 CVE-2016-9985 Information Exposure Through Log Files vulnerability in IBM Cognos Business Intelligence 10.1.1/10.2
IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user.
local
low complexity
ibm CWE-532
5.5
2017-03-08 CVE-2016-9006 Cross-site Scripting vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-03-08 CVE-2016-5933 7PK - Security Features vulnerability in IBM Tivoli Monitoring
IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass.
network
low complexity
ibm CWE-254
4.6
2017-03-08 CVE-2016-5894 Information Exposure vulnerability in IBM Websphere Commerce
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability.
local
high complexity
ibm CWE-200
5.1