|
268481
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_team_concert
|
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rationa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0285
|
2024-11-21 11:41 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268482
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_software_architect_design_manager rational_collaborative_lifecycle_management rational_team_concert rational_quality_manager rational_doors_next_generation rational_engineerin…
|
The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 …
|
CWE-611
XXE
|
CVE-2016-0284
|
2024-11-21 11:41 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268483
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_doors_next_generation rational_engineering_lifecycle_manager rational_collaborative_lifecycle_management rational_quality_manager rational_software_architect_design_manager ra…
|
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rationa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0273
|
2024-11-21 11:41 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268484
|
4.3 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authentica…
|
CWE-200
Information Exposure
|
CVE-2016-0377
|
2024-11-21 11:41 |
2016-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268485
|
7.8 |
HIGH
Local
|
ibm
|
security_guardium_database_activity_monitor
|
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privileges for command execu…
|
CWE-77
Command Injection
|
CVE-2016-0328
|
2024-11-21 11:41 |
2016-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268486
|
8.8 |
HIGH
Network
|
ibm
|
rational_collaborative_lifecycle_management rational_quality_manager
|
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote auth…
|
CWE-77
Command Injection
|
CVE-2016-0326
|
2024-11-21 11:41 |
2016-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268487
|
7.8 |
HIGH
Local
|
ibm
|
security_guardium
|
IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstr…
|
CWE-200
Information Exposure
|
CVE-2016-0247
|
2024-11-21 11:41 |
2016-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268488
|
6.1 |
MEDIUM
Network
|
ibm
|
security_guardium
|
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0246
|
2024-11-21 11:41 |
2016-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268489
|
4.3 |
MEDIUM
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message.
|
CWE-200
Information Exposure
|
CVE-2016-0242
|
2024-11-21 11:41 |
2016-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268490
|
8.8 |
HIGH
Network
|
ibm
|
security_guardium_database_activity_monitor
|
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by se…
|
CWE-284
Improper Access Control
|
CVE-2016-0241
|
2024-11-21 11:41 |
2016-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|