Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2017-03-31 CVE-2016-8935 Cross-site Scripting vulnerability in IBM Kenexa LMS
IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-03-27 CVE-2016-6056 Cross-site Scripting vulnerability in IBM Call Center FOR Commerce 9.3/9.4
IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-03-27 CVE-2016-9737 Cross-site Scripting vulnerability in IBM Tririga Application Platform
IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-03-27 CVE-2017-1143 Information Exposure vulnerability in IBM Kenexa Lcms Premier
IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
ibm CWE-200
3.5
2017-03-20 CVE-2016-2981 Information Exposure vulnerability in IBM Rational Collaborative Lifecycle Management
An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials.
local
low complexity
ibm CWE-200
2.1
2017-03-20 CVE-2016-9694 Cross-site Scripting vulnerability in IBM Rational Rhapsody Design Manager
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-03-20 CVE-2016-9696 Cross-site Scripting vulnerability in IBM Rational Rhapsody Design Manager
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to HTML injection.
network
ibm CWE-79
3.5
2017-03-20 CVE-2016-9697 Information Exposure vulnerability in IBM Rational Rhapsody Design Manager
An unspecified vulnerability in IBM Rhapsody DM 4.0, 5.0, and 6.0 could allow an attacker to perform a JSON Hijacking Attack.
network
high complexity
ibm CWE-200
2.1
2017-03-20 CVE-2017-1146 Cross-site Scripting vulnerability in IBM Content Navigator 2.0.3/3.0.0
IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-03-08 CVE-2016-5894 Information Exposure vulnerability in IBM Websphere Commerce
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability.
local
ibm CWE-200
1.9