Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-11-18 CVE-2013-5454 Information Exposure vulnerability in IBM Websphere Portal
IBM WebSphere Portal 6.0 through 6.0.1.7, 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF25, and 8.0 through 8.0.0.1 CF08 allows remote attackers to read arbitrary files via a modified URL.
network
ibm CWE-200
4.3
2013-11-18 CVE-2013-4034 Permissions, Privileges, and Access Controls vulnerability in IBM Cognos Business Intelligence
IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
ibm CWE-264
4.0
2013-11-18 CVE-2013-3030 Improper Input Validation vulnerability in IBM Cognos Business Intelligence
The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote attackers to cause a denial of service (temporary gateway outage) via crafted HTTP requests.
network
low complexity
ibm CWE-20
5.0
2013-11-13 CVE-2013-5450 Credentials Management vulnerability in IBM Security Appscan
IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.
network
high complexity
ibm CWE-255
4.0
2013-11-13 CVE-2013-5442 Cross-Site Scripting vulnerability in IBM products
Cross-site scripting (XSS) vulnerability in the Local Management Interface (LMI) in IBM Security Network Protection on XGS 5100 devices with firmware 5.1 before 5.1.0.6 and 5.1.1 before 5.1.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
4.3
2013-11-08 CVE-2013-3986 Buffer Errors vulnerability in IBM Lotus Sametime 8.5.2/8.5.2.1
IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension crash) via a crafted Audio Visual (AV) session.
network
ibm CWE-119
4.3
2013-11-08 CVE-2013-4050 Cross-Site Request Forgery (CSRF) vulnerability in IBM Lotus Domino 8.5.0/9.0.0.0
Cross-site request forgery (CSRF) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
network
ibm CWE-352
6.0
2013-11-06 CVE-2013-5387 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Platform Symphony 5.2/6.1/6.1.1
Buffer overflow in IBM Platform Symphony 5.2, 6.1, and 6.1.1 allows remote attackers to cause a denial of service (process crash or hang) via a malformed SOAP request with a large amount of request data.
network
ibm CWE-119
4.3
2013-11-01 CVE-2013-5431 Improper Input Validation vulnerability in IBM products
Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
ibm CWE-20
5.8
2013-10-28 CVE-2013-5430 Credentials Management vulnerability in IBM Security Appscan
The Jazz Team Server component in IBM Security AppScan Enterprise 8.x before 8.8 has a default username and password, which makes it easier for remote authenticated users to obtain unspecified access to this component by leveraging this credential information in an environment with applicable component installation details.
network
low complexity
ibm CWE-255
5.5