|
268521
|
5.6 |
MEDIUM
Network
|
ibm
|
security_identity_manager_adapter
|
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to s…
|
CWE-284
Improper Access Control
|
CVE-2016-0339
|
2024-11-21 11:41 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268522
|
6.2 |
MEDIUM
Local
|
ibm
|
security_identity_manager_adapter
|
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a configuration file or (2…
|
CWE-200
Information Exposure
|
CVE-2016-0338
|
2024-11-21 11:41 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268523
|
7.3 |
HIGH
Network
|
ibm
|
security_identity_manager_adapter
|
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes it easier for remote attackers to obtain access by…
|
CWE-255
Credentials Management
|
CVE-2016-0330
|
2024-11-21 11:41 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268524
|
5.4 |
MEDIUM
Network
|
ibm
|
bigfix_platform
|
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2016-0269
|
2024-11-21 11:41 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268525
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows rem…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0350
|
2024-11-21 11:41 |
2016-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268526
|
8.8 |
HIGH
Network
|
ibm
|
jazz_reporting_service
|
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, wh…
|
CWE-284
Improper Access Control
|
CVE-2016-0315
|
2024-11-21 11:41 |
2016-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268527
|
6.5 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacki…
|
NVD-CWE-noinfo
|
CVE-2016-0314
|
2024-11-21 11:41 |
2016-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268528
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows rem…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0313
|
2024-11-21 11:41 |
2016-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268529
|
7.8 |
HIGH
Local
|
ibm
|
i_access
|
IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-0287
|
2024-11-21 11:41 |
2016-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268530
|
8.2 |
HIGH
Local
|
ibm
|
urbancode_deploy
|
The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a server's identity in a JMS session or an HTTP session, which allows local users …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0271
|
2024-11-21 11:41 |
2016-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|