Vulnerabilities > IBM > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-03-31 CVE-2016-6111 XXE vulnerability in IBM Curam Social Program Management
IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data.
network
low complexity
ibm CWE-611
critical
9.1
2017-03-11 CVE-2017-5638 Improper Handling of Exceptional Conditions vulnerability in multiple products
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
network
low complexity
apache ibm lenovo hp oracle arubanetworks netapp CWE-755
critical
9.8
2017-02-15 CVE-2016-9706 XXE vulnerability in IBM Integration BUS and Websphere Message Broker
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data.
network
low complexity
ibm CWE-611
critical
9.1
2017-02-15 CVE-2016-0360 Deserialization of Untrusted Data vulnerability in IBM Websphere MQ JMS
IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath.
network
low complexity
ibm CWE-502
critical
9.8
2017-02-08 CVE-2016-9005 Improper Access Control vulnerability in IBM System Storage Ts3100-Ts3200 Tape Library D.60
IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and gain remote access to the system.
network
low complexity
ibm CWE-284
critical
9.8
2017-02-08 CVE-2016-8954 Use of Hard-coded Credentials vulnerability in IBM Dashdb Local
IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.
network
low complexity
ibm CWE-798
critical
9.8
2017-02-02 CVE-2016-6095 Improper Access Control vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
network
low complexity
ibm CWE-284
critical
9.8
2017-02-01 CVE-2016-8938 Improper Access Control vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server.
network
low complexity
ibm CWE-284
critical
10.0
2017-02-01 CVE-2016-6090 Unspecified vulnerability in IBM Websphere Commerce
IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performing of unauthorized administrative operations, and potentially causing a denial of service.
network
low complexity
ibm
critical
9.8
2017-02-01 CVE-2016-6082 Use After Free vulnerability in IBM Bigfix Platform
IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition.
network
low complexity
ibm CWE-416
critical
10.0