Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2017-07-21 CVE-2017-1381 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served.
local
low complexity
ibm CWE-200
2.1
2017-07-19 CVE-2017-1309 Cleartext Storage of Sensitive Information vulnerability in IBM Infosphere Master Data Management Server
IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-312
2.1
2017-07-17 CVE-2017-1181 Cleartext Transmission of Sensitive Information vulnerability in IBM Tivoli Monitoring 6.2.2.9/6.2.3.5/6.3.0.7
IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted.
local
ibm CWE-319
1.9
2017-07-13 CVE-2016-6019 Cross-site Scripting vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-07-13 CVE-2016-8952 Cross-site Scripting vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-07-12 CVE-2016-6114 Cross-site Scripting vulnerability in IBM Emptoris Sourcing
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-07-12 CVE-2016-8946 Cross-site Scripting vulnerability in IBM Emptoris Sourcing
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-07-12 CVE-2016-8948 Cross-site Scripting vulnerability in IBM Emptoris Sourcing
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-07-12 CVE-2016-8950 Cross-site Scripting vulnerability in IBM Emptoris Sourcing
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-07-10 CVE-2017-1284 Information Exposure vulnerability in IBM Websphere MQ 9.0.1/9.0.2
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to obtain sensitive information from WebSphere Application Server traces including user credentials.
local
ibm CWE-200
1.9