VYPR

Infosphere Streams

by IBM

CVEs (2)

  • CVE-2016-2867HigJul 2, 2016
    risk 0.46cvss 7.0epss 0.00

    IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors.

  • CVE-2017-1431MedAug 10, 2017
    risk 0.35cvss 5.4epss 0.00

    IBM InfoSphere Streams 4.0, 4.1, and 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127632.