|
272181
|
7.8 |
HIGH
Local
|
ibm
|
capacity_management_analytics
|
IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.
|
CWE-200
Information Exposure
|
CVE-2015-7432
|
2024-11-21 11:36 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272182
|
4.3 |
MEDIUM
Network
|
ibm
|
infosphere_master_data_management
|
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive …
|
CWE-200
Information Exposure
|
CVE-2015-7424
|
2024-11-21 11:36 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272183
|
5.4 |
MEDIUM
Network
|
ibm
|
infosphere_master_data_management
|
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7423
|
2024-11-21 11:36 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272184
|
4.3 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
IBM Curam Social Program Management 6.1.x before 6.1.1.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive document information by guessing the document id…
|
CWE-200
Information Exposure
|
CVE-2015-7401
|
2024-11-21 11:36 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272185
|
6.5 |
MEDIUM
Network
|
ibm
|
connections
|
XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denial of service (memory consumption) via cr…
|
CWE-399 CWE-611
Resource Management Errors XXE
|
CVE-2015-7461
|
2024-11-21 11:36 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272186
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. I…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7460
|
2024-11-21 11:36 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272187
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. I…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7459
|
2024-11-21 11:36 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272188
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. I…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7458
|
2024-11-21 11:36 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272189
|
3.3 |
LOW
Local
|
ibm
|
rational_collaborative_lifecycle_management rational_quality_manager rational_team_concert rational_requirements_composer rational_doors_next_generation rational_engineering_lifecycle_…
|
IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x befo…
|
CWE-200 CWE-326
Information Exposure Inadequate Encryption Strength
|
CVE-2015-7449
|
2024-11-21 11:36 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272190
|
4.8 |
MEDIUM
Network
|
ibm
|
rational_collaborative_lifecycle_management rational_quality_manager rational_team_concert rational_requirements_composer rational_doors_next_generation rational_engineering_lifecycle_…
|
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7471
|
2024-11-21 11:36 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|