Show filters
432 Total Results
Displaying 191-200 of 432
Sort by:
Attacker Value
Unknown

CVE-2016-9715

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119728.
0
Attacker Value
Unknown

CVE-2016-9718

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119732.
0
Attacker Value
Unknown

CVE-2016-9716

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119729.
0
Attacker Value
Unknown

CVE-2017-1309

Disclosure Date: July 19, 2017 (last updated November 26, 2024)
IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.
0
Attacker Value
Unknown

CVE-2017-1321

Disclosure Date: July 12, 2017 (last updated November 26, 2024)
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916.
Attacker Value
Unknown

CVE-2017-1310

Disclosure Date: June 29, 2017 (last updated November 26, 2024)
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.
0
Attacker Value
Unknown

CVE-2017-5645

Disclosure Date: April 17, 2017 (last updated November 08, 2023)
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Attacker Value
Unknown

CVE-2017-7269

Disclosure Date: March 27, 2017 (last updated July 26, 2024)
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.
Attacker Value
Unknown

CVE-2015-7493

Disclosure Date: February 08, 2017 (last updated November 26, 2024)
IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during installation processes that could expose sensitive information.
0
Attacker Value
Unknown

CVE-2016-9000

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.
0