Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2018-12-13 CVE-2017-1268 Cryptographic Issues vulnerability in IBM Security Guardium
IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input.
local
low complexity
ibm CWE-310
2.1
2018-12-13 CVE-2018-1653 Cross-site Scripting vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2018-12-13 CVE-2018-1667 Cross-site Scripting vulnerability in IBM Datapower Gateway
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2018-12-13 CVE-2018-1740 Cross-site Scripting vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2018-12-11 CVE-2018-1652 Improper Input Validation vulnerability in IBM Datapower Gateway and MQ Appliance
IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors.
local
low complexity
ibm CWE-20
2.1
2018-12-11 CVE-2018-1900 Cross-site Scripting vulnerability in IBM Curam Social Program Management
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2018-12-10 CVE-2018-1957 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed.
local
low complexity
ibm CWE-200
2.1
2018-12-07 CVE-2018-1896 Injection vulnerability in IBM Connections 5.0/5.5/6.0
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain.
network
ibm CWE-74
3.5
2018-12-06 CVE-2018-1505 Information Exposure vulnerability in IBM I2 Enterprise Insight Analysis 2.1.7/2.1.8
IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-200
2.1
2018-12-06 CVE-2018-1871 Cross-site Scripting vulnerability in IBM Financial Transaction Manager
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5