|
270761
|
6.1 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7431
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270762
|
8.4 |
HIGH
Local
|
apache
|
hadoop
|
The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to read or write to arbitrary GPFS data via unspecif…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7430
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270763
|
10.0 |
CRITICAL
Network
|
ibm
|
spectrum_protect_for_virtual_environments spectrum_protect_snapshot
|
The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 a…
|
CWE-78
OS Command
|
CVE-2015-7426
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270764
|
5.5 |
MEDIUM
Local
|
ibm
|
i_access
|
Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7422
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270765
|
4.0 |
MEDIUM
Local
|
ibm
|
i_access
|
AFP Workbench Viewer in IBM i Access 7.1 on Windows allows remote attackers to cause a denial of service (viewer crash) via a crafted workbench file.
|
CWE-20
Improper Input Validation
|
CVE-2015-7416
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270766
|
8.8 |
HIGH
Network
|
ibm
|
mashups_center
|
Cross-site request forgery (CSRF) vulnerability in Lotus Mashups in IBM Mashup Center 3.0.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequ…
|
CWE-352
Origin Validation Error
|
CVE-2015-7407
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270767
|
4.0 |
MEDIUM
Local
|
ibm
|
spectrum_scale general_parallel_file_system
|
IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect poin…
|
NVD-CWE-Other
|
CVE-2015-7403
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270768
|
7.7 |
HIGH
Network
|
ibm
|
mashups_center
|
The Lotus Mashups component in IBM Mashup Center 3.0.0.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an XML external entity declaration in conjunction with an…
|
CWE-399
Resource Management Errors
|
CVE-2015-7400
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270769
|
7.0 |
HIGH
Local
|
ibm
|
packaging_utility installation_manager
|
consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7442
|
2024-11-21 11:36 |
2016-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270770
|
5.4 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7402
|
2024-11-21 11:36 |
2016-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|