|
267681
|
7.5 |
HIGH
Network
|
jenkins redhat
|
jenkins openshift
|
The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2015-7539
|
2024-11-21 11:36 |
2016-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267682
|
7.5 |
HIGH
Network
|
openstack oracle
|
keystonemiddleware keystone solaris
|
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty b…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2015-7546
|
2024-11-21 11:36 |
2016-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267683
|
8.8 |
HIGH
Network
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2015-7538
|
2024-11-21 11:36 |
2016-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267684
|
8.8 |
HIGH
Network
|
redhat jenkins
|
openshift jenkins
|
Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecifie…
|
CWE-352
Origin Validation Error
|
CVE-2015-7537
|
2024-11-21 11:36 |
2016-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267685
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to wor…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7536
|
2024-11-21 11:36 |
2016-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267686
|
8.3 |
HIGH
Network
|
apache
|
hive
|
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table a…
|
CWE-287
Improper Authentication
|
CVE-2015-7521
|
2024-11-21 11:36 |
2016-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267687
|
7.5 |
HIGH
Network
|
ibm
|
jazz_reporting_service
|
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote attackers to cause a denial of service (Report Builder…
|
NVD-CWE-noinfo
|
CVE-2015-7464
|
2024-11-21 11:36 |
2016-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267688
|
5.9 |
MEDIUM
Local
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover an LDAP password via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-7488
|
2024-11-21 11:36 |
2016-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267689
|
4.1 |
MEDIUM
Local
|
ibm
|
maximo_asset_management maximo_for_transportation maximo_asset_management_essentials maximo_for_utilities maximo_for_nuclear_power smartcloud_control_desk tivoli_service_request_man…
|
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX002, 7.5.1, and 7.6.0 before 7.6.0.3…
|
CWE-200
Information Exposure
|
CVE-2015-7487
|
2024-11-21 11:36 |
2016-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267690
|
6.1 |
MEDIUM
Network
|
ibm
|
rational_software_architect_realtime rational_software_architect_for_websphere_software rational_software_architect_for_websphere_software\' rational_software_architect
|
Cross-site scripting (XSS) vulnerability in InfoSphere Data Architect (IDA), as distributed in IBM Rational Software Architect 8.5 through 9.5, Rational Software Architect for WebSphere Software (RSA…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7439
|
2024-11-21 11:36 |
2016-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|