|
264541
|
6.8 |
MEDIUM
Network
|
ibm
|
security_privileged_identity_manager_virtual_appliance
|
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive in…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2016-5972
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264542
|
7.1 |
HIGH
Network
|
ibm
|
security_privileged_identity_manager_virtual_appliance
|
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via…
|
CWE-200 CWE-611
Information Exposure XXE
|
CVE-2016-5971
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264543
|
6.5 |
MEDIUM
Network
|
ibm
|
security_privileged_identity_manager_virtual_appliance
|
Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files via a .. (dot do…
|
CWE-22 CWE-200
Path Traversal Information Exposure
|
CVE-2016-5970
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264544
|
8.8 |
HIGH
Network
|
ibm
|
security_privileged_identity_manager_virtual_appliance
|
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authenticated users to execute arbitrary code via unspe…
|
CWE-284
Improper Access Control
|
CVE-2016-5963
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264545
|
7.5 |
HIGH
Network
|
ibm
|
security_privileged_identity_manager_virtual_appliance
|
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive information by lever…
|
CWE-310
Cryptographic Issues
|
CVE-2016-5957
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264546
|
5.7 |
MEDIUM
Network
|
ibm
|
tivoli_storage_productivity_center spectrum_control
|
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
|
CWE-20
Improper Input Validation
|
CVE-2016-5947
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264547
|
6.5 |
MEDIUM
Network
|
ibm
|
spectrum_control tivoli_storage_productivity_center
|
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot…
|
CWE-200
Information Exposure
|
CVE-2016-5946
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264548
|
4.3 |
MEDIUM
Network
|
ibm
|
spectrum_control tivoli_storage_productivity_center
|
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.
|
CWE-284
Improper Access Control
|
CVE-2016-5945
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264549
|
5.4 |
MEDIUM
Network
|
ibm
|
spectrum_control tivoli_storage_productivity_center
|
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to inject arbitrary …
|
CWE-79
Cross-site Scripting
|
CVE-2016-5944
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264550
|
5.4 |
MEDIUM
Network
|
ibm
|
spectrum_control
|
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properti…
|
CWE-284
Improper Access Control
|
CVE-2016-5943
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|