NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
81800  CVE-2016-5958  IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information.    Medium  2017-02-08  2017-02-07  View
81799  CVE-2016-5953  IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.    4.3  Medium  2017-02-15  2017-02-15  View
81798  CVE-2016-5952  IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.    6.5  Medium  2017-02-15  2017-02-08  View
81797  CVE-2016-5951  IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.    3.5  Low  2017-02-15  2017-02-08  View
81796  CVE-2016-5950  IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user.    Medium  2017-02-15  2017-02-09  View

Page 1313 of 17672, showing 5 records out of 88360 total, starting on record 6561, ending on 6565

Actions