Vulnerabilities > IBM > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-02-01 | CVE-2016-3043 | Information Exposure vulnerability in IBM products IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. | 4.3 |
2017-02-01 | CVE-2016-3035 | Information Exposure vulnerability in IBM Security Appscan Source 9.0.1/9.0.2/9.0.3 IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server. | 5.0 |
2017-02-01 | CVE-2016-3029 | Cross-Site Request Forgery (CSRF) vulnerability in IBM products IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | 6.8 |
2017-02-01 | CVE-2016-3027 | XXE vulnerability in IBM products IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. | 5.5 |
2017-02-01 | CVE-2016-3023 | Information Exposure vulnerability in IBM products IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names. | 5.0 |
2017-02-01 | CVE-2016-3022 | Permission Issues vulnerability in IBM products IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions. | 4.0 |
2017-02-01 | CVE-2016-3021 | Information Exposure vulnerability in IBM products IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request. | 4.0 |
2017-02-01 | CVE-2016-3018 | Cross-site Scripting vulnerability in IBM products IBM Security Access Manager for Web is vulnerable to cross-site scripting. | 4.3 |
2017-02-01 | CVE-2016-3017 | Improperly Implemented Security Check for Standard vulnerability in IBM products IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations. | 5.0 |
2017-02-01 | CVE-2016-2987 | Information Exposure vulnerability in IBM products An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. | 4.0 |