|
266181
|
8.1 |
HIGH
Network
|
ibm
|
bigfix_remote_control
|
IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a brute-force approach.
|
CWE-254 CWE-284
7PK - Security Features Improper Access Control
|
CVE-2016-2929
|
2024-11-21 11:49 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266182
|
4.3 |
MEDIUM
Network
|
ibm
|
bigfix_remote_control
|
IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2016-2928
|
2024-11-21 11:49 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266183
|
5.9 |
MEDIUM
Network
|
ibm
|
bigfix_remote_control
|
IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms …
|
CWE-200
Information Exposure
|
CVE-2016-2927
|
2024-11-21 11:49 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266184
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_team_concert rational_rhapsody_design_manager rational_engineering_lifecycle_manager rational_quality_manager rational_collaborative_lifecycle_management rational_software_arc…
|
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 …
|
CWE-79
Cross-site Scripting
|
CVE-2016-2926
|
2024-11-21 11:49 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266185
|
9.1 |
CRITICAL
Network
|
ibm
|
security_access_manager security_access_manager_for_web
|
IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leve…
|
CWE-78
OS Command
|
CVE-2016-3028
|
2024-11-21 11:49 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266186
|
8.1 |
HIGH
Network
|
ibm
|
security_access_manager security_access_manager_for_mobile
|
IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attac…
|
CWE-254
7PK - Security Features
|
CVE-2016-3025
|
2024-11-21 11:49 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266187
|
8.5 |
HIGH
Network
|
ibm
|
tivoli_storage_manager_for_virtual_environments
|
IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 and 7.1.x before 7.1.6 allows remote authenticated …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2988
|
2024-11-21 11:49 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266188
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_engineering_lifecycle_manager rational_team_concert rational_quality_manager rational_doors_next_generation rational_rhapsody_design_manager
|
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x before 6.0.1 iFix6, Rational Team Concert 6.x before 6…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2986
|
2024-11-21 11:49 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266189
|
7.0 |
HIGH
Local
|
ibm
|
spectrum_scale general_parallel_file_system
|
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via craf…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2985
|
2024-11-21 11:49 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266190
|
7.0 |
HIGH
Local
|
ibm
|
spectrum_scale general_parallel_file_system
|
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via craf…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2984
|
2024-11-21 11:49 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|