Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-05 CVE-2017-1254 XXE vulnerability in IBM Security Guardium
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2017-06-27 CVE-2017-1322 XXE vulnerability in IBM API Connect
IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
8.2
2017-06-27 CVE-2017-1297 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM products
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code.
local
low complexity
ibm CWE-119
7.3
2017-06-27 CVE-2017-1105 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM products
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service.
local
low complexity
ibm CWE-119
7.1
2017-06-27 CVE-2016-9738 7PK - Security Features vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-254
7.5
2017-06-23 CVE-2017-1347 SQL Injection vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8
2017-06-15 CVE-2017-1379 Information Exposure vulnerability in IBM API Connect
IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Portal.
network
low complexity
ibm CWE-200
7.5
2017-06-13 CVE-2016-9984 Permissions, Privileges, and Access Controls vulnerability in IBM Maximo Asset Management 7.5/7.6
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator.
network
low complexity
ibm CWE-264
8.8
2017-06-08 CVE-2017-1319 Inadequate Encryption Strength vulnerability in IBM Tivoli Federated Identity Manager 6.2.0/6.2.1/6.2.2
IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie.
network
low complexity
ibm CWE-326
7.5
2017-06-08 CVE-2016-9991 Cross-Site Request Forgery (CSRF) vulnerability in IBM Sterling Selling and Fulfillment Foundation
IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.0