Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-02-03 CVE-2016-8212 Improper Resource Shutdown or Release vulnerability in Dell Bsafe Crypto-J
An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2.
network
low complexity
dell CWE-404
7.5
2017-02-03 CVE-2016-8211 Path Traversal vulnerability in Dell EMC Data Protection Advisor
EMC Data Protection Advisor 6.1.x, EMC Data Protection Advisor 6.2, EMC Data Protection Advisor 6.2.1, EMC Data Protection Advisor 6.2.2, EMC Data Protection Advisor 6.2.3 prior to patch 446 has a path traversal vulnerability that may potentially be exploited by malicious users to compromise the affected system.
network
low complexity
dell CWE-22
7.5
2017-02-02 CVE-2017-1093 Unspecified vulnerability in IBM AIX 6.1/7.1/7.2
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.
local
low complexity
ibm
7.8
2017-02-02 CVE-2016-6103 Cross-Site Request Forgery (CSRF) vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2017-02-02 CVE-2017-5218 SQL Injection vulnerability in Sagecrm
A SQL Injection issue was discovered in SageCRM 7.x before 7.3 SP3.
network
low complexity
sagecrm CWE-89
8.8
2017-02-01 CVE-2017-5630 Injection vulnerability in PHP Pear 1.10.1
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.
network
low complexity
php CWE-74
7.5
2017-02-01 CVE-2016-9739 Credentials Management vulnerability in IBM Security Identity Manager
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-255
7.8
2017-02-01 CVE-2016-9008 Improper Access Control vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.
network
low complexity
ibm CWE-284
7.5
2017-02-01 CVE-2016-8932 Improper Access Control vulnerability in IBM Kenexa LMS
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
network
low complexity
ibm CWE-284
8.8
2017-02-01 CVE-2016-8931 Improper Access Control vulnerability in IBM Kenexa LMS
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
network
low complexity
ibm CWE-284
8.8