NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81800 | CVE-2016-5958 | IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. | 2 | 5 | Medium | 2017-02-08 | 2017-02-07 | View | |
81799 | CVE-2016-5953 | IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-15 | View | |
81798 | CVE-2016-5952 | IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. | 2 | 6.5 | Medium | 2017-02-15 | 2017-02-08 | View | |
81797 | CVE-2016-5951 | IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 2 | 3.5 | Low | 2017-02-15 | 2017-02-08 | View | |
81796 | CVE-2016-5950 | IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user. | 2 | 4 | Medium | 2017-02-15 | 2017-02-09 | View |
Page 1313 of 17672, showing 5 records out of 88360 total, starting on record 6561, ending on 6565