Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2019-06-17 CVE-2019-4174 Improper Privilege Management vulnerability in IBM Cognos Controller
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-269
3.3
2019-06-17 CVE-2019-4177 Improper Privilege Management vulnerability in IBM Cognos Controller
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-269
3.3
2019-06-06 CVE-2019-4161 Unspecified vulnerability in IBM Security Information Queue 1.0.0/1.0.1/1.0.2
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 discloses sensitive information to unauthorized users.
local
low complexity
ibm
3.3
2019-06-06 CVE-2019-4218 Improper Privilege Management vulnerability in IBM Security Information Queue 1.0.0/1.0.1/1.0.2
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-269
3.3
2019-06-06 CVE-2019-4048 Improper Privilege Management vulnerability in IBM products
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine.
low complexity
ibm CWE-269
2.1
2019-05-29 CVE-2019-4139 Cross-site Scripting vulnerability in IBM Cognos Analytics 11.0.0/11.1.0/11.1.1
IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2019-05-29 CVE-2019-4184 Cross-site Scripting vulnerability in IBM Jazz Reporting Service
IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2019-05-20 CVE-2018-2005 Information Exposure vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local attacker with elevated permissions.
local
low complexity
ibm CWE-200
2.1
2019-05-16 CVE-2018-1975 Cross-site Scripting vulnerability in IBM Rational Doors web Access
IBM Rational DOORS Web Access 9.5.1 through 9.5.2.9, and 9.6 through 9.6.1.9 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2019-05-10 CVE-2019-4204 Cross-site Scripting vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5