Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2017-07-05 CVE-2017-1176 Information Exposure vulnerability in IBM Maximo Asset Management
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments.
local
low complexity
ibm CWE-200
2.1
2017-07-05 CVE-2017-1207 Insufficiently Protected Credentials vulnerability in IBM Integration BUS and Websphere Message Broker
IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
2.1
2017-07-05 CVE-2017-1208 Cross-site Scripting vulnerability in IBM Maximo Asset Management
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-06-28 CVE-2017-1106 Cross-site Scripting vulnerability in IBM Curam Social Program Management
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-06-27 CVE-2017-1105 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM products
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service.
local
low complexity
ibm linux microsoft CWE-119
3.6
2017-06-27 CVE-2017-1234 Cross-site Scripting vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-06-23 CVE-2016-5893 Information Exposure vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-200
2.1
2017-06-23 CVE-2017-1132 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-06-23 CVE-2017-1302 Information Exposure vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls.
local
low complexity
ibm CWE-200
2.1
2017-06-23 CVE-2017-1348 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5