|
266701
|
8.8 |
HIGH
Network
|
ibm
|
security_identity_manager
|
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the aut…
|
CWE-352
Origin Validation Error
|
CVE-2016-0335
|
2024-11-21 11:41 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266702
|
9.8 |
CRITICAL
Network
|
ibm
|
security_identity_manager_virtual_appliance
|
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers t…
|
CWE-254
7PK - Security Features
|
CVE-2016-0332
|
2024-11-21 11:41 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266703
|
7.8 |
HIGH
Local
|
ibm
|
security_identity_manager_virtual_appliance
|
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors. IBM X-Force ID:…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0327
|
2024-11-21 11:41 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266704
|
8.8 |
HIGH
Network
|
ibm
|
security_identity_manager_virtual_appliance
|
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges vi…
|
CWE-77
Command Injection
|
CVE-2016-0324
|
2024-11-21 11:41 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266705
|
4.3 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928.
|
CWE-200
Information Exposure
|
CVE-2016-0358
|
2024-11-21 11:41 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266706
|
6.5 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-…
|
CWE-352
Origin Validation Error
|
CVE-2016-0356
|
2024-11-21 11:41 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266707
|
6.5 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-…
|
CWE-352
Origin Validation Error
|
CVE-2016-0355
|
2024-11-21 11:41 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266708
|
5.5 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which coul…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-0354
|
2024-11-21 11:41 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266709
|
3.7 |
LOW
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the mi…
|
CWE-200
Information Exposure
|
CVE-2016-0238
|
2024-11-21 11:41 |
2017-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266710
|
6.5 |
MEDIUM
Network
|
ibm
|
cognos_business_intelligence
|
IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker c…
|
CWE-611
XXE
|
CVE-2016-0254
|
2024-11-21 11:41 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|