Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-10 CVE-2017-1623 Cross-site Scripting vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting.
network
ibm CWE-79
4.3
2018-01-10 CVE-2017-1534 Open Redirect vulnerability in IBM products
IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
ibm CWE-601
5.8
2018-01-10 CVE-2017-1533 Cross-site Scripting vulnerability in IBM Security Access Manager 9.0 Firmware
IBM Security Access Manager Appliance 9.0.3 is vulnerable to cross-site scripting.
network
ibm CWE-79
4.3
2018-01-10 CVE-2017-1459 Incorrect Permission Assignment for Critical Resource vulnerability in IBM products
IBM Security Access Manager Appliance 8.0.0 and 9.0.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
network
ibm CWE-732
4.9
2018-01-10 CVE-2016-9722 Improper Access Control vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
network
ibm CWE-284
4.9
2018-01-09 CVE-2017-1671 Path Traversal vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
5.0
2018-01-09 CVE-2017-1668 Open Redirect vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
ibm CWE-601
5.8
2018-01-09 CVE-2017-1666 XXE vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
5.5
2018-01-09 CVE-2017-1612 Unspecified vulnerability in IBM Websphere MQ
IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' user.
local
low complexity
ibm
4.6
2018-01-09 CVE-2017-1493 Improper Privilege Management vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls.
network
low complexity
ibm CWE-269
5.5