Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-19 CVE-2018-1362 Unspecified vulnerability in IBM Curam Social Program Management
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 within Citizen Portal could allow an authenticated user to withdraw other user's submitted applications from the system and possibly obtain privileges.
network
ibm
6.0
2018-01-19 CVE-2017-1693 Insufficient Session Expiration vulnerability in IBM Integration BUS
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out.
network
ibm CWE-613
6.8
2018-01-16 CVE-2016-0219 XXE vulnerability in IBM products
XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via crafted XML data.
network
low complexity
ibm CWE-611
4.0
2018-01-16 CVE-2016-0215 Improper Input Validation vulnerability in IBM DB2
IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.
network
low complexity
ibm hp linux microsoft oracle CWE-20
4.0
2018-01-16 CVE-2015-7484 Information Exposure vulnerability in IBM Rational Engineering Lifecycle Manager
IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remote authenticated users with access to lifecycle projects to obtain sensitive information by sending a crafted URL to the Lifecycle Query Engine.
network
low complexity
ibm CWE-200
4.0
2018-01-12 CVE-2016-0335 Cross-Site Request Forgery (CSRF) vulnerability in IBM Security Identity Manager
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
network
ibm CWE-352
6.8
2018-01-12 CVE-2016-0332 7PK - Security Features vulnerability in IBM Security Identity Manager Virtual Appliance
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
network
low complexity
ibm CWE-254
5.0
2018-01-12 CVE-2016-0327 Permissions, Privileges, and Access Controls vulnerability in IBM Security Identity Manager Virtual Appliance
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors.
local
low complexity
ibm CWE-264
4.6
2018-01-11 CVE-2018-1361 Cross-site Scripting vulnerability in IBM Websphere Portal 8.5.0.0/9.0.0.0
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting.
network
ibm CWE-79
4.3
2018-01-10 CVE-2017-3765 Improper Authentication vulnerability in Lenovo Enterprise Network Operating System
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces.
local
high complexity
lenovo ibm CWE-287
6.2