|
266191
|
8.1 |
HIGH
Network
|
ibm
|
bigfix_platform
|
IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected.
|
CWE-77
Command Injection
|
CVE-2016-0396
|
2024-11-21 11:41 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266192
|
3.3 |
LOW
Local
|
ibm
|
websphere_message_broker integration_bus
|
IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.
|
CWE-275
Permission Issues
|
CVE-2016-0394
|
2024-11-21 11:41 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266193
|
3.7 |
LOW
Network
|
ibm
|
bigfix_platform
|
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the mi…
|
CWE-200
Information Exposure
|
CVE-2016-0297
|
2024-11-21 11:41 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266194
|
3.3 |
LOW
Local
|
ibm
|
bigfix_platform
|
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2016-0296
|
2024-11-21 11:41 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266195
|
5.4 |
MEDIUM
Network
|
ibm
|
campaign
|
IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute s…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0265
|
2024-11-21 11:41 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266196
|
7.5 |
HIGH
Network
|
ibm
|
jazz_reporting_service
|
The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of…
|
CWE-284
Improper Access Control
|
CVE-2016-0319
|
2024-11-21 11:41 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266197
|
5.0 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by lev…
|
CWE-284
Improper Access Control
|
CVE-2016-0318
|
2024-11-21 11:41 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266198
|
6.5 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-0317
|
2024-11-21 11:41 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266199
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 before iFix003 allows remote authenticated users to…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0316
|
2024-11-21 11:41 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266200
|
3.7 |
LOW
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by triggering an exception.
|
CWE-200
Information Exposure
|
CVE-2016-0378
|
2024-11-21 11:41 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|