Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-04 CVE-2017-1727 Information Exposure Through Log Files vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system.
network
low complexity
ibm CWE-532
4.0
2018-01-04 CVE-2017-1673 Cross-site Scripting vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to cross-site scripting.
network
ibm CWE-79
4.3
2018-01-04 CVE-2017-1672 Cross-Site Request Forgery (CSRF) vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
ibm CWE-352
6.8
2018-01-04 CVE-2017-1669 Information Exposure vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters.
network
ibm CWE-200
4.3
2018-01-04 CVE-2017-1665 Inadequate Encryption Strength vulnerability in multiple products
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
ibm debian CWE-326
4.3
2018-01-04 CVE-2017-1664 Inadequate Encryption Strength vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
ibm CWE-326
4.3
2018-01-02 CVE-2017-1557 Unspecified vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that could cause a channel process to cease processing further requests.
network
low complexity
ibm
4.0
2017-12-27 CVE-2017-1698 Information Exposure vulnerability in IBM Websphere Portal
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system.
network
low complexity
ibm CWE-200
5.0
2017-12-27 CVE-2017-1191 Unspecified vulnerability in IBM products
An undisclosed vulnerability in CLM applications (including IBM Rational Collaborative Lifecycle Management 4.0, 5.0, and 6.0) with potential for failure to restrict URL Access.
network
low complexity
ibm
4.0
2017-12-20 CVE-2017-1757 SQL Injection vulnerability in IBM Security Guardium
IBM Security Guardium 10.0 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
6.5