Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2019-06-06 CVE-2019-4218 Improper Privilege Management vulnerability in IBM Security Information Queue 1.0.0/1.0.1/1.0.2
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-269
3.3
2019-06-06 CVE-2019-4048 Improper Privilege Management vulnerability in IBM products
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine.
low complexity
ibm CWE-269
2.1
2019-05-22 CVE-2018-1991 Information Exposure vulnerability in IBM API Connect
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers.
network
low complexity
ibm CWE-200
2.7
2019-05-20 CVE-2018-2005 Information Exposure vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local attacker with elevated permissions.
local
low complexity
ibm CWE-200
3.3
2019-05-07 CVE-2019-4207 Unspecified vulnerability in IBM Tririga Application Platform 3.5.3.0/3.6.0.0
IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available to a local user that could be used in further attacks against the system.
local
low complexity
ibm
3.3
2019-04-25 CVE-2019-4146 Unspecified vulnerability in IBM Sterling B2B Integrator 6.0.0.0/6.0.0.1
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to obtain sensitive document information under unusual circumstances.
network
high complexity
ibm
3.1
2019-04-02 CVE-2018-1623 Information Exposure vulnerability in IBM Security Privileged Identity Manager 2.1.1
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-200
3.3
2019-02-04 CVE-2018-1962 Session Fixation vulnerability in IBM Security Identity Manager
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed.
local
low complexity
ibm CWE-384
3.3
2019-01-08 CVE-2018-1993 Information Exposure vulnerability in IBM Spectrum Scale
IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file.
local
low complexity
ibm CWE-200
3.3
2018-12-13 CVE-2018-1804 Session Fixation vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute on authorization tokens or session cookies.
network
high complexity
ibm CWE-384
3.7