Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2012-08-17 CVE-2012-2164 Permissions, Privileges, and Access Controls vulnerability in IBM Rational Clearquest
The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering attack.
network
low complexity
ibm CWE-264
5.5
2012-08-17 CVE-2012-0744 Information Exposure vulnerability in IBM Rational Clearquest
IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) HelloHTML.jsp, (8) HelloVXMLError.jsp, (9) HelloVXML.jsp, (10) HelloWMLError.jsp, (11) HelloWML.jsp, or (12) cqweb/j_security_check sample script.
network
low complexity
ibm CWE-200
5.0
2012-08-17 CVE-2012-3308 Cross-Site Scripting vulnerability in IBM Sametime
Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via an IM chat.
network
ibm CWE-79
4.3
2012-08-17 CVE-2012-3294 Cross-Site Request Forgery (CSRF) vulnerability in IBM Websphere MQ and Websphere MQ Managed File Transfer
Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, and WebSphere MQ - Managed File Transfer 7.5, allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add user accounts via the /wmqfteconsole/Filespaces URI, (2) modify permissions via the /wmqfteconsole/FileSpacePermisssions URI, or (3) add MQ Message Descriptor (MQMD) user accounts via the /wmqfteconsole/UploadUsers URI.
network
ibm CWE-352
6.8
2012-08-17 CVE-2012-2206 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere MQ
The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.
network
ibm CWE-264
3.5
2012-08-08 CVE-2012-2203 Permissions, Privileges, and Access Controls vulnerability in IBM products
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses the PKCS #12 file format for certificate objects without enforcing file integrity, which makes it easier for remote attackers to spoof SSL servers via vectors involving insertion of an arbitrary root Certification Authority (CA) certificate.
network
low complexity
ibm CWE-264
7.5
2012-08-08 CVE-2012-2191 Improper Input Validation vulnerability in IBM products
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.
network
low complexity
ibm CWE-20
5.0
2012-08-06 CVE-2012-2188 Permissions, Privileges, and Access Controls vulnerability in IBM products
IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a (1) $ (dollar sign) or (2) & (ampersand) character.
local
low complexity
ibm CWE-264
7.2
2012-07-30 CVE-2012-2163 Permissions, Privileges, and Access Controls vulnerability in IBM Scale OUT Network Attached Storage 1.1/1.3.1
IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via the (1) Command Line Interface or (2) Graphical User Interface, related to a "code injection" issue.
network
low complexity
ibm CWE-264
critical
9.0
2012-07-30 CVE-2012-0723 Improper Input Validation vulnerability in IBM AIX and Vios
The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
local
low complexity
ibm CWE-20
4.9