Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-07 CVE-2018-1756 SQL Injection vulnerability in IBM Security Identity Governance and Intelligence 5.2.3.2/5.2.4
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
7.5
2018-08-24 CVE-2018-1699 SQL Injection vulnerability in IBM Maximo Asset Management
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8
2018-08-20 CVE-2018-1517 Improper Input Validation vulnerability in multiple products
A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data.
network
low complexity
ibm redhat CWE-20
7.5
2018-08-15 CVE-2018-1455 Cross-Site Request Forgery (CSRF) vulnerability in IBM Tivoli Application Dependency Discovery Manager 7.2.2/7.3.0
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2018-08-06 CVE-2018-1551 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name.
network
high complexity
ibm CWE-732
7.5
2018-08-06 CVE-2017-1411 Insufficiently Protected Credentials vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-522
7.5
2018-08-06 CVE-2017-1396 Permission Issues vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
network
low complexity
ibm CWE-275
8.1
2018-08-06 CVE-2017-1366 Inadequate Encryption Strength vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2018-08-03 CVE-2018-1524 Insecure Default Initialization of Resource vulnerability in IBM products
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system.
network
low complexity
ibm CWE-1188
8.8
2018-08-01 CVE-2018-1595 Unspecified vulnerability in IBM Platform Symphony and Spectrum Symphony
IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary commands due to improper handling of user supplied input.
network
low complexity
ibm
8.8