Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-07 CVE-2016-8971 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault which would result in the box having to be rebooted to resume normal operations.
network
low complexity
ibm CWE-119
6.5
2017-03-01 CVE-2016-8232 Cross-site Scripting vulnerability in IBM Advanced Management Module Firmware
Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM's IP address to send a crafted URL that could inject a malicious script to access a user's AMM data such as cookies or other session information.
network
low complexity
ibm CWE-79
6.1
2017-03-01 CVE-2016-5932 Cross-site Scripting vulnerability in IBM Connections
IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-23 CVE-2016-6055 Cross-site Scripting vulnerability in IBM products
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-23 CVE-2016-5883 Cross-site Scripting vulnerability in IBM Inotes
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-02-22 CVE-2016-8986 Improper Access Control vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests.
network
low complexity
ibm CWE-284
6.5
2017-02-22 CVE-2016-8915 Improper Access Control vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process.
network
low complexity
ibm CWE-284
6.5
2017-02-22 CVE-2016-3052 Information Exposure vulnerability in IBM Websphere MQ
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network.
network
high complexity
ibm CWE-200
5.9
2017-02-22 CVE-2016-3013 Data Processing Errors vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling.
network
low complexity
ibm CWE-19
6.5
2017-02-16 CVE-2016-6062 Cross-site Scripting vulnerability in IBM Resilient 26.0/26.1/26.2
IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1