Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2017-02-01 CVE-2016-9703 Session Fixation vulnerability in IBM Security Identity Manager Virtual Appliance
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
local
low complexity
ibm CWE-384
2.1
2017-02-01 CVE-2016-9739 Credentials Management vulnerability in IBM Security Identity Manager
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-255
2.1
2017-02-01 CVE-2016-8967 Credentials Management vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm hp linux microsoft oracle CWE-255
2.1
2017-02-01 CVE-2016-0265 Cross-site Scripting vulnerability in IBM Campaign
IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
network
ibm CWE-79
3.5
2017-02-01 CVE-2016-0296 Information Exposure Through Log Files vulnerability in IBM Bigfix Platform
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.
local
low complexity
ibm CWE-532
2.1
2017-02-01 CVE-2016-0394 Permission Issues vulnerability in IBM Integration BUS and Websphere Message Broker
IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.
local
low complexity
ibm CWE-275
2.1
2017-02-01 CVE-2016-3016 Insufficient Verification of Data Authenticity vulnerability in IBM products
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker to load malicious code.
network
ibm CWE-345
3.5
2017-02-01 CVE-2016-3024 Information Exposure vulnerability in IBM products
IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-200
2.1
2017-02-01 CVE-2016-3034 Inadequate Encryption Strength vulnerability in IBM Security Appscan Source 9.0.1/9.0.2/9.0.3
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.
local
low complexity
ibm CWE-326
2.1
2017-02-01 CVE-2016-5880 Cross-site Scripting vulnerability in IBM Domino and Inotes
IBM iNotes is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5