Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-12-21 CVE-2013-5413 Improper Authentication vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
network
ibm CWE-287
4.3
2013-12-21 CVE-2013-5411 Improper Input Validation vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote attackers to inject links and trigger unintended navigation or actions via unspecified vectors.
network
ibm CWE-20
4.3
2013-12-21 CVE-2013-5409 SQL Injection vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
ibm CWE-89
6.5
2013-12-21 CVE-2013-5407 Improper Input Validation vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.
network
ibm CWE-20
4.9
2013-12-21 CVE-2013-4070 Information Exposure vulnerability in IBM Spss Collaboration and Deployment Services
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to discover an internal password via unspecified vectors.
network
low complexity
ibm CWE-200
5.0
2013-12-21 CVE-2013-4069 Information Exposure vulnerability in IBM Spss Collaboration and Deployment Services
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
ibm CWE-200
5.0
2013-12-21 CVE-2013-4063 Cross-Site Scripting vulnerability in IBM Lotus Domino and Lotus Inotes
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPRs PTHN9AQMV7 and TCLE98ZKRP.
network
ibm CWE-79
4.3
2013-12-21 CVE-2013-4046 Improper Input Validation vulnerability in IBM Spss Collaboration and Deployment Services
Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
ibm CWE-20
5.8
2013-12-21 CVE-2013-4045 Cross-Site Scripting vulnerability in IBM Spss Collaboration and Deployment Services
Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
4.3
2013-12-21 CVE-2013-4044 Information Exposure vulnerability in IBM Spss Collaboration and Deployment Services
IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request.
network
low complexity
ibm CWE-200
4.0