|
248951
|
5.5 |
MEDIUM
Local
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM X-Force ID: 126525.
|
CWE-200
Information Exposure
|
CVE-2017-1349
|
2024-11-21 12:21 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248952
|
5.4 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1348
|
2024-11-21 12:21 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248953
|
8.8 |
HIGH
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or …
|
CWE-89
SQL Injection
|
CVE-2017-1347
|
2024-11-21 12:21 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248954
|
5.5 |
MEDIUM
Local
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID: 125456.
|
CWE-200
Information Exposure
|
CVE-2017-1302
|
2024-11-21 12:21 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248955
|
6.5 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.
|
CWE-200
Information Exposure
|
CVE-2017-1193
|
2024-11-21 12:21 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248956
|
5.4 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1132
|
2024-11-21 12:21 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248957
|
6.5 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-Force ID: 121375.
|
CWE-200
Information Exposure
|
CVE-2017-1131
|
2024-11-21 12:21 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248958
|
4.3 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the…
|
CWE-269
Improper Privilege Management
|
CVE-2017-1326
|
2024-11-21 12:21 |
2017-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248959
|
5.3 |
MEDIUM
Network
|
ibm
|
websphere_mq
|
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a denial of service to the MQXR channel when trace is enabled. IBM X-Force ID: 121155.
|
NVD-CWE-noinfo
|
CVE-2017-1117
|
2024-11-21 12:21 |
2017-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248960
|
6.2 |
MEDIUM
Local
|
ibm
|
elastic_storage_server
|
IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing of an unsupported configuration, where users appl…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1304
|
2024-11-21 12:21 |
2017-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|