Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2016-11-30 CVE-2016-2963 Cross-Site Request Forgery (CSRF) vulnerability in IBM Bigfix Remote Control 9.1.2
Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
network
low complexity
ibm CWE-352
8.8
2016-11-30 CVE-2016-2958 Information Exposure vulnerability in IBM Connections 4.0.0.0/4.5.0.0/5.0.0.0
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic" e-mail address in a response.
network
low complexity
ibm CWE-200
4.3
2016-11-30 CVE-2016-2957 Information Exposure vulnerability in IBM Connections 4.0.0.0/4.5.0.0/5.0.0.0
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.
network
low complexity
ibm CWE-200
4.3
2016-11-30 CVE-2016-2953 Cryptographic Issues vulnerability in IBM Connections 4.0.0.0/4.5.0.0/5.0.0.0
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
network
high complexity
ibm CWE-310
3.7
2016-11-30 CVE-2016-2952 Information Exposure vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.
network
high complexity
ibm CWE-200
3.7
2016-11-30 CVE-2016-2951 Cryptographic Issues vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
network
high complexity
ibm CWE-310
3.7
2016-11-30 CVE-2016-2950 SQL Injection vulnerability in IBM Bigfix Remote Control 9.1.2
SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
ibm CWE-89
6.5
2016-11-30 CVE-2016-2949 Information Exposure vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.
local
low complexity
ibm CWE-200
3.3
2016-11-30 CVE-2016-2948 Use of Hard-coded Credentials vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.
local
low complexity
ibm CWE-798
7.8
2016-11-30 CVE-2016-2944 Improper Authentication vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
network
low complexity
ibm CWE-287
critical
9.8