|
265681
|
7.5 |
HIGH
Network
|
ibm
|
security_access_manager_for_web_7.0_firmware security_access_manager_for_web_8.0_firmware security_access_manager_for_mobile security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Reference #: 1…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2016-5919
|
2024-11-21 11:55 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265682
|
7.8 |
HIGH
Local
|
ibm
|
aix vios
|
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6079
|
2024-11-21 11:55 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265683
|
5.3 |
MEDIUM
Local
|
ibm
|
cognos_disclosure_management
|
IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document. IBM Reference #: 1991584.
|
CWE-284
Improper Access Control
|
CVE-2016-6077
|
2024-11-21 11:55 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265684
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_requirements_composer rational_doors_next_generation
|
An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547.
|
CWE-200
Information Exposure
|
CVE-2016-6060
|
2024-11-21 11:55 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265685
|
8.8 |
HIGH
Network
|
ibm
|
tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware tivoli_storage_flashcopy_manager_for_vmware
|
IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted fr…
|
CWE-352
Origin Validation Error
|
CVE-2016-6033
|
2024-11-21 11:55 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265686
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
powerlogic_pm8ecc_firmware
|
An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-5818
|
2024-11-21 11:55 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265687
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
ion7600 ion7300 ion8650 ion7500 ion5000 ion8800
|
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. No authentication is confi…
|
CWE-284
Improper Access Control
|
CVE-2016-5815
|
2024-11-21 11:55 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265688
|
5.3 |
MEDIUM
Network
|
visonic
|
powerlink2_firmware
|
An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. When a specific URL to an image is accessed, the downloaded image carries with it source code used …
|
CWE-200
Information Exposure
|
CVE-2016-5813
|
2024-11-21 11:55 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265689
|
6.1 |
MEDIUM
Network
|
visonic
|
powerlink2_firmware
|
An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. User controlled input is not neutralized prior to being placed in web page output (CROSS-SITE SCRIP…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5811
|
2024-11-21 11:55 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265690
|
8.8 |
HIGH
Network
|
schneider-electric
|
ion7600 ion7300 ion8650 ion7500 ion5000 ion8800
|
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. There is no CSRF Token gen…
|
CWE-352
Origin Validation Error
|
CVE-2016-5809
|
2024-11-21 11:55 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|