Vendor CVEs
IBM
All CVEs
8,825 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-1555 | Med | 0.28 | 4.3 | 0.01 | Sep 25, 2017 | IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545. | ||
| CVE-2016-2976 | Med | 0.28 | 4.3 | 0.01 | Aug 29, 2017 | IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by viewing the meeting report history. IBM X-Force ID: 113936. | ||
| CVE-2016-2966 | Med | 0.28 | 4.3 | 0.01 | Aug 29, 2017 | IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-Force ID: 113847. | ||
| CVE-2016-0358 | Med | 0.28 | 4.3 | 0.01 | Aug 29, 2017 | IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928. | ||
| CVE-2016-2977 | Med | 0.28 | 4.3 | 0.01 | Aug 29, 2017 | IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID: 113937. | ||
| CVE-2016-2969 | Med | 0.28 | 4.3 | 0.01 | Aug 29, 2017 | IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM X-Force ID: 113850. | ||
| CVE-2016-2959 | Med | 0.28 | 4.3 | 0.01 | Aug 29, 2017 | IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Force ID: 113804. | ||
| CVE-2016-10503 | Med | 0.28 | 4.3 | 0.01 | Aug 29, 2017 | IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. IBM X-Force ID: 113803. | ||
| CVE-2016-2970 | Med | 0.28 | 4.3 | 0.01 | Aug 29, 2017 | IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851. | ||
| CVE-2017-1377 | Med | 0.28 | 4.3 | 0.01 | Aug 10, 2017 | IBM Runbook Automation reveals sensitive information in error messages that could be used in further attacks against the system. IBM X-Force ID: 126874. | ||
| CVE-2017-1357 | Med | 0.28 | 4.3 | 0.01 | Aug 9, 2017 | IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684. | ||
| CVE-2016-6018 | Med | 0.28 | 4.3 | 0.01 | Jul 19, 2017 | IBM Emptoris Contract Management 10.0 and 10.1 reveals detailed error messages in certain features that could cause an attacker to gain additional information to conduct further attacks. IBM X-Force ID: 116738. | ||
| CVE-2017-1157 | Med | 0.28 | 4.3 | 0.01 | Jul 5, 2017 | IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788. | ||
| CVE-2016-9700 | Med | 0.28 | 4.3 | 0.01 | Jul 5, 2017 | IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528. | ||
| CVE-2017-1326 | Med | 0.28 | 4.3 | 0.01 | Jun 22, 2017 | IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060. | ||
| CVE-2017-1099 | Med | 0.28 | 4.3 | 0.03 | Jun 13, 2017 | IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659. | ||
| CVE-2016-8987 | Med | 0.28 | 4.3 | 0.01 | Jun 8, 2017 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view. | ||
| CVE-2016-3051 | Med | 0.28 | 4.3 | 0.01 | Jun 7, 2017 | IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714. | ||
| CVE-2016-9735 | Med | 0.28 | 4.3 | 0.01 | May 15, 2017 | IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781, | ||
| CVE-2017-1141 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2017 | IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907. | ||
| CVE-2016-9978 | Med | 0.28 | 4.3 | 0.01 | Apr 20, 2017 | IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254. | ||
| CVE-2016-8923 | Med | 0.28 | 4.3 | 0.01 | Apr 20, 2017 | IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536. | ||
| CVE-2017-1152 | Med | 0.28 | 4.3 | 0.01 | Apr 14, 2017 | IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293. | ||
| CVE-2016-8926 | Med | 0.28 | 4.3 | 0.01 | Apr 14, 2017 | IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539. | ||
| CVE-2017-1171 | Med | 0.28 | 4.3 | 0.01 | Mar 31, 2017 | The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to execute Application actions they do not have access to. IBM Reference #: 2001083. | ||
| CVE-2017-1155 | Med | 0.28 | 4.3 | 0.01 | Mar 20, 2017 | IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to another user's reports using a specially crafted HTTP request. IBM Reference #: 1999754. | ||
| CVE-2016-8973 | Med | 0.28 | 4.3 | 0.01 | Mar 20, 2017 | IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server. IBM Reference #: 1999960. | ||
| CVE-2016-9730 | Med | 0.28 | 4.3 | 0.00 | Mar 7, 2017 | IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549. | ||
| CVE-2016-6060 | Med | 0.28 | 4.3 | 0.01 | Feb 15, 2017 | An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547. | ||
| CVE-2016-0308 | Med | 0.28 | 4.3 | 0.01 | Feb 8, 2017 | IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images. | ||
| CVE-2016-0307 | Med | 0.28 | 4.3 | 0.01 | Feb 8, 2017 | IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses. | ||
| CVE-2016-9748 | Med | 0.28 | 4.3 | 0.01 | Feb 8, 2017 | IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system. | ||
| CVE-2016-2866 | Med | 0.28 | 4.3 | 0.01 | Feb 8, 2017 | An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user. | ||
| CVE-2016-6094 | Med | 0.28 | 4.3 | 0.01 | Feb 7, 2017 | IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data. | ||
| CVE-2016-0320 | Med | 0.28 | 4.3 | 0.01 | Feb 1, 2017 | IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes. | ||
| CVE-2016-8912 | Med | 0.28 | 4.3 | 0.01 | Feb 1, 2017 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user. | ||
| CVE-2016-6122 | Med | 0.28 | 4.3 | 0.01 | Feb 1, 2017 | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users. | ||
| CVE-2016-6044 | Med | 0.28 | 4.3 | 0.01 | Feb 1, 2017 | IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy. | ||
| CVE-2016-6028 | Med | 0.28 | 4.3 | 0.01 | Feb 1, 2017 | IBM Jazz technology based products might allow an attacker to view work item titles that they do not have privilege to view. | ||
| CVE-2016-5949 | Med | 0.28 | 4.3 | 0.01 | Feb 1, 2017 | IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request. | ||
| CVE-2016-5898 | Med | 0.28 | 4.3 | 0.01 | Feb 1, 2017 | IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information. | ||
| CVE-2016-2987 | Med | 0.28 | 4.3 | 0.01 | Feb 1, 2017 | An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. | ||
| CVE-2016-2958 | Med | 0.28 | 4.3 | 0.02 | Nov 30, 2016 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic" e-mail address in a response. | ||
| CVE-2016-2957 | Med | 0.28 | 4.3 | 0.01 | Nov 30, 2016 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response. | ||
| CVE-2016-2928 | Med | 0.28 | 4.3 | 0.01 | Nov 25, 2016 | IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs. | ||
| CVE-2016-0377 | Med | 0.28 | 4.3 | 0.02 | Oct 22, 2016 | The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors. | ||
| CVE-2016-0242 | Med | 0.28 | 4.3 | 0.01 | Oct 22, 2016 | IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message. | ||
| CVE-2016-5945 | Med | 0.28 | 4.3 | 0.01 | Sep 26, 2016 | IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request. | ||
| CVE-2016-3000 | Med | 0.28 | 4.3 | 0.01 | Sep 26, 2016 | The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL. | ||
| CVE-2016-3615 | Med | 0.28 | 5.3 | 0.06 | Jul 21, 2016 | Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: DML. |
- risk 0.28cvss 4.3epss 0.01
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545.
- risk 0.28cvss 4.3epss 0.01
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by viewing the meeting report history. IBM X-Force ID: 113936.
- risk 0.28cvss 4.3epss 0.01
IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-Force ID: 113847.
- risk 0.28cvss 4.3epss 0.01
IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928.
- risk 0.28cvss 4.3epss 0.01
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID: 113937.
- risk 0.28cvss 4.3epss 0.01
IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM X-Force ID: 113850.
- risk 0.28cvss 4.3epss 0.01
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Force ID: 113804.
- risk 0.28cvss 4.3epss 0.01
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. IBM X-Force ID: 113803.
- risk 0.28cvss 4.3epss 0.01
IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851.
- risk 0.28cvss 4.3epss 0.01
IBM Runbook Automation reveals sensitive information in error messages that could be used in further attacks against the system. IBM X-Force ID: 126874.
- risk 0.28cvss 4.3epss 0.01
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684.
- risk 0.28cvss 4.3epss 0.01
IBM Emptoris Contract Management 10.0 and 10.1 reveals detailed error messages in certain features that could cause an attacker to gain additional information to conduct further attacks. IBM X-Force ID: 116738.
- risk 0.28cvss 4.3epss 0.01
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.
- risk 0.28cvss 4.3epss 0.01
IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528.
- risk 0.28cvss 4.3epss 0.01
IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.
- risk 0.28cvss 4.3epss 0.03
IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659.
- risk 0.28cvss 4.3epss 0.01
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.
- risk 0.28cvss 4.3epss 0.01
IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.
- risk 0.28cvss 4.3epss 0.01
IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781,
- risk 0.28cvss 4.3epss 0.01
IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907.
- risk 0.28cvss 4.3epss 0.01
IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.
- risk 0.28cvss 4.3epss 0.01
IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536.
- risk 0.28cvss 4.3epss 0.01
IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.
- risk 0.28cvss 4.3epss 0.01
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539.
- risk 0.28cvss 4.3epss 0.01
The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to execute Application actions they do not have access to. IBM Reference #: 2001083.
- risk 0.28cvss 4.3epss 0.01
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to another user's reports using a specially crafted HTTP request. IBM Reference #: 1999754.
- risk 0.28cvss 4.3epss 0.01
IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server. IBM Reference #: 1999960.
- risk 0.28cvss 4.3epss 0.00
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.
- risk 0.28cvss 4.3epss 0.01
An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547.
- risk 0.28cvss 4.3epss 0.01
IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images.
- risk 0.28cvss 4.3epss 0.01
IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses.
- risk 0.28cvss 4.3epss 0.01
IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.
- risk 0.28cvss 4.3epss 0.01
An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user.
- risk 0.28cvss 4.3epss 0.01
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.
- risk 0.28cvss 4.3epss 0.01
IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.
- risk 0.28cvss 4.3epss 0.01
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.
- risk 0.28cvss 4.3epss 0.01
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users.
- risk 0.28cvss 4.3epss 0.01
IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.
- risk 0.28cvss 4.3epss 0.01
IBM Jazz technology based products might allow an attacker to view work item titles that they do not have privilege to view.
- risk 0.28cvss 4.3epss 0.01
IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request.
- risk 0.28cvss 4.3epss 0.01
IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information.
- risk 0.28cvss 4.3epss 0.01
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker.
- risk 0.28cvss 4.3epss 0.02
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic" e-mail address in a response.
- risk 0.28cvss 4.3epss 0.01
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.
- risk 0.28cvss 4.3epss 0.01
IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.
- risk 0.28cvss 4.3epss 0.02
The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message.
- risk 0.28cvss 4.3epss 0.01
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.
- risk 0.28cvss 4.3epss 0.01
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.
- risk 0.28cvss 5.3epss 0.06
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: DML.
Page 113 of 177