Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2012-04-22 CVE-2012-0740 Cross-Site Scripting vulnerability in IBM Tivoli Directory Server
Cross-site scripting (XSS) vulnerability in the Web Admin Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.22 and 6.3 before 6.3.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
4.3
2012-04-22 CVE-2012-0726 Cryptographic Issues vulnerability in IBM Tivoli Directory Server
The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communication via the TLS Handshake Protocol.
network
low complexity
ibm CWE-310
6.4
2012-03-22 CVE-2012-1837 Information Exposure vulnerability in IBM Tivoli Endpoint Manager 8.0/8.1
The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
network
low complexity
ibm CWE-200
5.0
2012-03-22 CVE-2012-0719 Cross-Site Scripting vulnerability in IBM Tivoli Endpoint Manager 8.0/8.1/8.2
Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint Manager (TEM) 8 before 8.2 patch 3 allows remote attackers to inject arbitrary web script or HTML via the ScheduleParam parameter to the webreports program.
network
ibm CWE-79
4.3
2012-03-20 CVE-2012-0712 Resource Management Errors vulnerability in IBM DB2 9.5/9.7/9.8
The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.
network
low complexity
ibm CWE-399
4.0
2012-03-20 CVE-2012-0710 Improper Input Validation vulnerability in IBM DB2
IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request.
network
low complexity
ibm CWE-20
5.0
2012-03-20 CVE-2012-0709 Improper Input Validation vulnerability in IBM DB2 9.5/9.7/9.8
IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements.
network
low complexity
ibm CWE-20
4.0
2012-03-13 CVE-2012-0195 Cross-Site Scripting vulnerability in IBM products
Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote attackers to inject arbitrary web script or HTML via the display name.
network
ibm CWE-79
4.3
2012-03-13 CVE-2011-4819 Cross-Site Scripting vulnerability in IBM products
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allow remote attackers to inject arbitrary web script or HTML via the uisesionid parameter to (1) maximo.jsp or (2) the default URI under ui/.
network
ibm CWE-79
4.3
2012-03-13 CVE-2011-4818 Improper Input Validation vulnerability in IBM products
Open redirect vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the uisessionid parameter to an unspecified component.
network
ibm CWE-20
4.3