|
265641
|
5.5 |
MEDIUM
Local
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by a local user.
|
CWE-200
Information Exposure
|
CVE-2016-2941
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265642
|
5.4 |
MEDIUM
Network
|
ibm
|
biginsights
|
IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted UR…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2924
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265643
|
7.8 |
HIGH
Local
|
ibm
|
aix
|
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3053
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265644
|
2.7 |
LOW
Network
|
ibm
|
security_access_manager_for_web_8.0_firmware security_access_manager_for_mobile security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements which could allow the attacker to view information in the back-end da…
|
CWE-89
SQL Injection
|
CVE-2016-3046
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265645
|
3.7 |
LOW
Network
|
ibm
|
security_access_manager security_access_manager_for_mobile security_access_manager_for_web
|
IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer he…
|
CWE-200
Information Exposure
|
CVE-2016-3045
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265646
|
5.9 |
MEDIUM
Network
|
ibm
|
security_access_manager_for_web_7.0_firmware security_access_manager_for_web_8.0_firmware security_access_manager_for_mobile security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit t…
|
CWE-200
Information Exposure
|
CVE-2016-3043
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265647
|
5.3 |
MEDIUM
Network
|
ibm
|
security_appscan_source
|
IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.
|
CWE-200
Information Exposure
|
CVE-2016-3035
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265648
|
4.4 |
MEDIUM
Local
|
ibm
|
security_appscan_source
|
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2016-3034
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265649
|
8.8 |
HIGH
Network
|
ibm
|
security_access_manager_9.0_firmware security_access_manager_for_mobile_8.0_firmware security_access_manager_for_web_8.0_firmware
|
IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website tr…
|
CWE-352
Origin Validation Error
|
CVE-2016-3029
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265650
|
6.5 |
MEDIUM
Network
|
ibm
|
security_access_manager_9.0_firmware security_access_manager_for_mobile_8.0_firmware security_access_manager_for_web_8.0_firmware
|
IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnera…
|
CWE-611
XXE
|
CVE-2016-3027
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|