Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-02-01 CVE-2016-6126 Path Traversal vulnerability in IBM Kenexa LMS on Cloud
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
6.5
2017-02-01 CVE-2016-6125 Cross-site Scripting vulnerability in IBM Kenexa LMS on Cloud
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-6123 Cross-site Scripting vulnerability in IBM Kenexa LMS on Cloud
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-6122 Information Exposure vulnerability in IBM Kenexa LMS on Cloud
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users.
network
low complexity
ibm CWE-200
4.3
2017-02-01 CVE-2016-6113 Cross-site Scripting vulnerability in IBM Domino and Inotes
IBM Verse is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-02-01 CVE-2016-6085 Improper Access Control vulnerability in IBM Bigfix Platform
IBM BigFix Platform could allow an attacker on the local network to crash the BES and relay servers.
low complexity
ibm CWE-284
6.5
2017-02-01 CVE-2016-6084 Improper Input Validation vulnerability in IBM Bigfix Platform 9.0/9.1
IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request.
low complexity
ibm CWE-20
6.5
2017-02-01 CVE-2016-6080 Information Exposure vulnerability in IBM Websphere Message Broker 8.0
The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.
network
low complexity
ibm CWE-200
5.3
2017-02-01 CVE-2016-6072 Cross-site Scripting vulnerability in IBM products
IBM Maximo Asset Management is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-6061 Cross-site Scripting vulnerability in IBM Rational Collaborative Lifecycle Management
IBM Jazz Foundation is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4