Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-09-15 CVE-2015-0110 Improper Access Control vulnerability in IBM products
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.
network
low complexity
ibm CWE-284
4.0
2017-09-13 CVE-2017-1556 Improper Input Validation vulnerability in IBM API Connect 5.0.7.0/5.0.7.1/5.0.7.2
IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and cause the system to slow or hang.
network
low complexity
ibm CWE-20
4.0
2017-09-13 CVE-2017-1508 Unspecified vulnerability in IBM Informix Dynamic Server 12.10
IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges.
local
low complexity
ibm linux
6.8
2017-09-12 CVE-2017-1520 Improper Authentication vulnerability in IBM DB2 and DB2 Connect
IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT.
4.3
2017-09-12 CVE-2017-1519 Improper Input Validation vulnerability in IBM DB2 and DB2 Connect
IBM DB2 10.5 and 11.1 contains a denial of service vulnerability.
4.3
2017-09-12 CVE-2017-1352 Command Injection vulnerability in IBM Maximo Asset Management 7.5/7.6
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file.
network
ibm CWE-77
6.0
2017-09-12 CVE-2017-1162 Information Exposure vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
5.0
2017-09-07 CVE-2014-9565 Cross-Site Request Forgery (CSRF) vulnerability in IBM En6131 Firmware and Ib6131 Firmware
Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earlier.
network
ibm CWE-352
6.8
2017-09-07 CVE-2017-1189 Cross-site Scripting vulnerability in IBM Websphere Portal
IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting.
network
ibm CWE-79
4.3
2017-09-05 CVE-2017-1491 Unspecified vulnerability in IBM Qradar Network Security 5.4
IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
network
low complexity
ibm
5.0