CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95755  CVE-2016-8935  Candidate  IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999483.  Assigned (20161025)  None (candidate not yet proposed)    View
95754  CVE-2016-8934  Candidate  IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.  Assigned (20161025)  None (candidate not yet proposed)    View
95753  CVE-2016-8933  Candidate  IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.  Assigned (20161025)  None (candidate not yet proposed)    View
95752  CVE-2016-8932  Candidate  IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.  Assigned (20161025)  None (candidate not yet proposed)    View
95751  CVE-2016-8931  Candidate  IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.  Assigned (20161025)  None (candidate not yet proposed)    View

Page 1793 of 20943, showing 5 records out of 104715 total, starting on record 8961, ending on 8965

Actions