Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2016-9994

Disclosure Date: March 01, 2017 (last updated November 26, 2024)
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1976805.
0
Attacker Value
Unknown

CVE-2016-9993

Disclosure Date: March 01, 2017 (last updated November 26, 2024)
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.
0
Attacker Value
Unknown

CVE-2016-9992

Disclosure Date: March 01, 2017 (last updated November 26, 2024)
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.
0
Attacker Value
Unknown

CVE-2016-5952

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
0
Attacker Value
Unknown

CVE-2016-5948

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown

CVE-2016-5937

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
0
Attacker Value
Unknown

CVE-2016-5950

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user.
0