Vulnerabilities > IBM > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-11-13 CVE-2017-1710 Unspecified vulnerability in IBM products
A vulnerability in the Service Assistant GUI in IBM Storwize V7000 (2076) 8.1 could allow a remote attacker to perform a privilege escalation.
network
low complexity
ibm
critical
9.8
2017-11-13 CVE-2017-1221 Weak Password Requirements vulnerability in IBM Bigfix Platform 9.2/9.5
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2017-10-05 CVE-2016-8937 Improper Authentication vulnerability in IBM Tivoli Storage Manager
The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication.
network
low complexity
ibm CWE-287
critical
9.8
2017-08-29 CVE-2017-1376 Inclusion of Functionality from Untrusted Control Sphere vulnerability in IBM Operations Analytics Predictive Insights
A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges.
network
low complexity
ibm CWE-829
critical
9.8
2017-08-02 CVE-2017-1383 XXE vulnerability in IBM Infosphere Information Server 11.3/11.5/9.1
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
critical
9.1
2017-07-13 CVE-2016-8964 7PK - Security Features vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
network
low complexity
ibm CWE-254
critical
9.8
2017-07-05 CVE-2017-1253 OS Command Injection vulnerability in IBM Security Guardium
IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system.
network
low complexity
ibm CWE-78
critical
9.9
2017-07-05 CVE-2017-1175 SQL Injection vulnerability in IBM Maximo Asset Management
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
critical
9.8
2017-07-05 CVE-2017-1269 SQL Injection vulnerability in IBM Security Guardium
IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
critical
9.8
2017-06-15 CVE-2017-1197 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Bigfix Security Compliance Analytics 1.9.70
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
network
low complexity
ibm CWE-307
critical
9.8