Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-08-24 CVE-2018-1755 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC).
network
ibm CWE-200
4.3
2018-08-24 CVE-2018-1699 SQL Injection vulnerability in IBM Maximo Asset Management
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
6.5
2018-08-20 CVE-2018-1656 Path Traversal vulnerability in multiple products
The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files.
4.3
2018-08-20 CVE-2018-1517 Improper Input Validation vulnerability in multiple products
A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data.
network
low complexity
ibm redhat CWE-20
5.0
2018-08-17 CVE-2017-1732 Information Exposure vulnerability in IBM Security Access Manager for Enterprise Single Sign-On 8.2.2
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-200
5.0
2018-08-15 CVE-2018-1455 Cross-Site Request Forgery (CSRF) vulnerability in IBM Tivoli Application Dependency Discovery Manager 7.2.2/7.3.0
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
ibm CWE-352
6.8
2018-08-13 CVE-2017-1749 Path Traversal vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
5.0
2018-08-13 CVE-2017-1286 Information Exposure vulnerability in IBM Urbancode Deploy
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked.
network
low complexity
ibm CWE-200
4.0
2018-08-13 CVE-2016-2922 Improper Certificate Validation vulnerability in IBM Rational Clearquest
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname.
network
ibm CWE-295
4.3
2018-08-06 CVE-2018-1551 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name.
network
ibm CWE-732
6.0