|
267091
|
3.3 |
LOW
Local
|
ibm
|
sterling_connect\
|
IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0380
|
2024-11-21 11:41 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267092
|
6.5 |
MEDIUM
Network
|
ibm
|
general_parallel_file_system
|
IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticate…
|
NVD-CWE-noinfo
|
CVE-2016-0361
|
2024-11-21 11:41 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267093
|
3.7 |
LOW
Network
|
ibm
|
aix vios
|
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter cras…
|
CWE-20
Improper Input Validation
|
CVE-2016-0281
|
2024-11-21 11:41 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267094
|
3.7 |
LOW
Network
|
ibm
|
vios aix
|
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
|
CWE-254
7PK - Security Features
|
CVE-2016-0266
|
2024-11-21 11:41 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267095
|
5.4 |
MEDIUM
Network
|
ibm
|
information_server_framework infosphere_information_governance_catalog infosphere_information_server_business_glossary
|
Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server F…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0280
|
2024-11-21 11:41 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267096
|
5.3 |
MEDIUM
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.
|
CWE-200
Information Exposure
|
CVE-2016-0393
|
2024-11-21 11:41 |
2016-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267097
|
6.2 |
MEDIUM
Local
|
ibm
|
personal_communications
|
IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging acces…
|
CWE-200
Information Exposure
|
CVE-2016-0321
|
2024-11-21 11:41 |
2016-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267098
|
4.3 |
MEDIUM
Network
|
ibm
|
security_identity_manager_adapter
|
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web site.
|
CWE-284
Improper Access Control
|
CVE-2016-0357
|
2024-11-21 11:41 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267099
|
7.4 |
HIGH
Local
|
ibm
|
security_identity_manager_adapter
|
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allows remote attackers to hijack sessions by leveragin…
|
CWE-284
Improper Access Control
|
CVE-2016-0340
|
2024-11-21 11:41 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267100
|
5.6 |
MEDIUM
Network
|
ibm
|
security_identity_manager_adapter
|
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to s…
|
CWE-284
Improper Access Control
|
CVE-2016-0339
|
2024-11-21 11:41 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|