Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-27 CVE-2017-1120 Cross-site Scripting vulnerability in IBM Websphere Portal 8.5/9.0
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-03-27 CVE-2016-9737 Cross-site Scripting vulnerability in IBM Tririga Application Platform
IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-03-27 CVE-2016-6056 Cross-site Scripting vulnerability in IBM Call Center for Commerce 9.3/9.4
IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-03-20 CVE-2017-1155 Information Exposure vulnerability in IBM Algo ONE 4.9.1/5.0.0/5.1.0
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to another user's reports using a specially crafted HTTP request.
network
low complexity
ibm CWE-200
4.3
2017-03-20 CVE-2017-1146 Cross-site Scripting vulnerability in IBM Content Navigator 2.0.3/3.0.0
IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-03-20 CVE-2016-9696 Cross-site Scripting vulnerability in IBM Rational Rhapsody Design Manager
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to HTML injection.
network
low complexity
ibm CWE-79
5.4
2017-03-20 CVE-2016-9694 Cross-site Scripting vulnerability in IBM Rational Rhapsody Design Manager
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-03-20 CVE-2016-8973 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Rational Rhapsody Design Manager
IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server.
network
low complexity
ibm CWE-434
4.3
2017-03-20 CVE-2016-2981 Information Exposure vulnerability in IBM Rational Collaborative Lifecycle Management
An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials.
low complexity
ibm CWE-200
6.8
2017-03-08 CVE-2016-9985 Information Exposure Through Log Files vulnerability in IBM Cognos Business Intelligence 10.1.1/10.2
IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user.
local
low complexity
ibm CWE-532
5.5