|
267121
|
8.0 |
HIGH
Network
|
ibm
|
tririga_application_platform
|
Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to hijack the auth…
|
CWE-352
Origin Validation Error
|
CVE-2016-0386
|
2024-11-21 11:41 |
2016-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267122
|
8.8 |
HIGH
Network
|
ibm
|
messagesight
|
JMS Client in IBM MessageSight 1.1.x through 1.1.0.1, 1.2.x through 1.2.0.3, and 2.0.x through 2.0.0.0 allows remote authenticated users to obtain administrator privileges for executing arbitrary com…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0375
|
2024-11-21 11:41 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267123
|
8.8 |
HIGH
Network
|
ibm
|
tririga_application_platform
|
The builder tools in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allow remote authenticated users to gain privileges for application modification v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0374
|
2024-11-21 11:41 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267124
|
5.9 |
MEDIUM
Network
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication …
|
CWE-200
Information Exposure
|
CVE-2016-0365
|
2024-11-21 11:41 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267125
|
4.3 |
MEDIUM
Network
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authent…
|
CWE-200
Information Exposure
|
CVE-2016-0364
|
2024-11-21 11:41 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267126
|
7.7 |
HIGH
Network
|
ibm
|
tririga_application_platform
|
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger ne…
|
NVD-CWE-Other
|
CVE-2016-0362
|
2024-11-21 11:41 |
2016-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267127
|
6.5 |
MEDIUM
Network
|
ibm
|
business_process_manager
|
IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a…
|
CWE-284
Improper Access Control
|
CVE-2016-0349
|
2024-11-21 11:41 |
2016-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267128
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0322
|
2024-11-21 11:41 |
2016-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267129
|
8.1 |
HIGH
Network
|
ibm
|
domino
|
The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass …
|
CWE-284
Improper Access Control
|
CVE-2016-0304
|
2024-11-21 11:41 |
2016-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267130
|
6.5 |
MEDIUM
Network
|
ibm
|
security_guardium
|
Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL.
|
CWE-200
Information Exposure
|
CVE-2016-0298
|
2024-11-21 11:41 |
2016-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|