Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2016-08-08 CVE-2016-0380 Permissions, Privileges, and Access Controls vulnerability in IBM Sterling Connect:Direct
IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.
local
low complexity
ibm CWE-264
2.1
2016-08-08 CVE-2016-2912 Cross-site Scripting vulnerability in IBM Rational Publishing Engine 2.0.1
Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2016-08-08 CVE-2016-2925 Cross-site Scripting vulnerability in IBM Websphere Portal
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2016-08-08 CVE-2016-3054 Cross-site Scripting vulnerability in IBM Filenet Workplace 4.0.2
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.
network
ibm CWE-79
3.5
2016-08-08 CVE-2016-3059 Information Exposure vulnerability in IBM products
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local users to discover a cleartext SQL Server password by reading the Task List in the MMC GUI.
local
low complexity
ibm CWE-200
2.1
2016-07-17 CVE-2016-0321 Information Exposure vulnerability in IBM Personal Communications
IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim account and executing a PowerShell script.
local
low complexity
ibm CWE-200
2.1
2016-07-15 CVE-2016-0269 Cross-site Scripting vulnerability in IBM Bigfix Platform
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2016-07-15 CVE-2016-0338 Information Exposure vulnerability in IBM Security Identity Manager Adapter
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a configuration file or (2) examining a process.
local
low complexity
ibm CWE-200
2.1
2016-07-08 CVE-2016-0252 Information Exposure vulnerability in IBM Control Center and Sterling Control Center
IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors.
local
ibm CWE-200
1.9
2016-07-08 CVE-2016-0287 Information Exposure vulnerability in IBM I Access 7.1
IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.
local
low complexity
ibm microsoft CWE-200
2.1