|
257231
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a request that will then be rendered and executed in the context of the Administrative user when …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9257
|
2024-11-21 12:00 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257232
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded between the time the permissions are chan…
|
CWE-362
Race Condition
|
CVE-2016-9256
|
2024-11-21 12:00 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257233
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket profile.
|
CWE-20
Improper Input Validation
|
CVE-2016-9253
|
2024-11-21 12:00 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257234
|
8.8 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9251
|
2024-11-21 12:00 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257235
|
5.5 |
MEDIUM
Local
|
ibm
|
tivoli_storage_manager
|
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472.
|
CWE-200
Information Exposure
|
CVE-2016-8916
|
2024-11-21 12:00 |
2017-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257236
|
5.9 |
MEDIUM
Network
|
ibm
|
bigfix_inventory
|
IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851.
|
CWE-255
Credentials Management
|
CVE-2016-8962
|
2024-11-21 12:00 |
2017-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257237
|
5.6 |
MEDIUM
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit th…
|
CWE-79
Cross-site Scripting
|
CVE-2016-8924
|
2024-11-21 12:00 |
2017-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257238
|
4.3 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that th…
|
CWE-200
Information Exposure
|
CVE-2016-8923
|
2024-11-21 12:00 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257239
|
5.4 |
MEDIUM
Network
|
ibm
|
tivoli_application_dependency_discovery_manager
|
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering…
|
CWE-79
Cross-site Scripting
|
CVE-2016-8927
|
2024-11-21 12:00 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257240
|
4.3 |
MEDIUM
Network
|
ibm
|
tivoli_application_dependency_discovery_manager
|
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539.
|
CWE-200
Information Exposure
|
CVE-2016-8926
|
2024-11-21 12:00 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|