|
269171
|
7.8 |
HIGH
Local
|
ibm
|
capacity_management_analytics
|
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107863.
|
CWE-200
Information Exposure
|
CVE-2015-7434
|
2024-11-21 11:36 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269172
|
7.8 |
HIGH
Local
|
ibm
|
capacity_management_analytics
|
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107862.
|
CWE-200
Information Exposure
|
CVE-2015-7433
|
2024-11-21 11:36 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269173
|
7.8 |
HIGH
Local
|
ibm
|
capacity_management_analytics
|
IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.
|
CWE-200
Information Exposure
|
CVE-2015-7432
|
2024-11-21 11:36 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269174
|
4.3 |
MEDIUM
Network
|
ibm
|
infosphere_master_data_management
|
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive …
|
CWE-200
Information Exposure
|
CVE-2015-7424
|
2024-11-21 11:36 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269175
|
5.4 |
MEDIUM
Network
|
ibm
|
infosphere_master_data_management
|
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7423
|
2024-11-21 11:36 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269176
|
4.3 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
IBM Curam Social Program Management 6.1.x before 6.1.1.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive document information by guessing the document id…
|
CWE-200
Information Exposure
|
CVE-2015-7401
|
2024-11-21 11:36 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269177
|
6.5 |
MEDIUM
Network
|
ibm
|
connections
|
XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denial of service (memory consumption) via cr…
|
CWE-399 CWE-611
Resource Management Errors XXE
|
CVE-2015-7461
|
2024-11-21 11:36 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269178
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. I…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7460
|
2024-11-21 11:36 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269179
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. I…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7459
|
2024-11-21 11:36 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269180
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. I…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7458
|
2024-11-21 11:36 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|