Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-07-13 CVE-2017-1308 Files or Directories Accessible to External Parties vulnerability in IBM Daeja Viewone 4.1.5/4.1.5.1/5.0
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls.
network
low complexity
ibm CWE-552
6.5
2017-07-13 CVE-2016-8952 Cross-site Scripting vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-07-13 CVE-2016-6019 Cross-site Scripting vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-07-12 CVE-2017-1321 Cross-site Scripting vulnerability in IBM products
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-07-12 CVE-2017-1285 Improper Input Validation vulnerability in IBM Websphere MQ 9.0.1/9.0.2
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to remain in a running state but not process messages.
network
low complexity
ibm CWE-20
6.5
2017-07-12 CVE-2016-8953 Open Redirect vulnerability in IBM Emptoris Sourcing
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
5.4
2017-07-12 CVE-2016-8950 Cross-site Scripting vulnerability in IBM Emptoris Sourcing
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-07-12 CVE-2016-8948 Cross-site Scripting vulnerability in IBM Emptoris Sourcing
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-07-12 CVE-2016-8947 Open Redirect vulnerability in IBM Emptoris Sourcing
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.1
2017-07-12 CVE-2016-8946 Cross-site Scripting vulnerability in IBM Emptoris Sourcing
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4