Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2017-02-08 CVE-2016-5918 Information Exposure vulnerability in IBM Tivoli Storage Manager FOR Space Management
IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace output if the password access option is prompt and the password is changed.
1.9
2017-02-08 CVE-2015-5013 Insufficiently Protected Credentials vulnerability in IBM products
The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.
local
low complexity
ibm CWE-522
2.1
2017-02-08 CVE-2016-6032 Cross-site Scripting vulnerability in IBM Rational Collaborative Lifecycle Management
IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-02-08 CVE-2017-1127 Cross-site Scripting vulnerability in IBM products
IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-02-08 CVE-2017-1128 Cross-site Scripting vulnerability in IBM products
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-02-07 CVE-2016-6092 Information Exposure vulnerability in IBM products
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-200
2.1
2017-02-07 CVE-2016-6097 Information Exposure vulnerability in IBM products
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-200
2.1
2017-02-01 CVE-2016-0217 Cross-site Scripting vulnerability in IBM Cognos Analytics
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input.
network
ibm CWE-79
3.5
2017-02-01 CVE-2016-0218 Cross-site Scripting vulnerability in IBM Cognos Business Intelligence
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
network
ibm CWE-79
3.5
2017-02-01 CVE-2016-2924 Cross-site Scripting vulnerability in IBM Biginsights 4.2
IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
network
ibm CWE-79
3.5