NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 81794 | CVE-2016-5948 | IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 2 | 3.5 | Low | 2017-02-15 | 2017-02-09 | View | |
| 42114 | CVE-2013-7398 | main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-09 | View | |
| 81795 | CVE-2016-5949 | IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request. | 2 | 4 | Medium | 2017-02-15 | 2017-02-09 | View | |
| 81796 | CVE-2016-5950 | IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user. | 2 | 4 | Medium | 2017-02-15 | 2017-02-09 | View | |
| 81803 | CVE-2016-5980 | IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 2 | 3.5 | Low | 2017-02-15 | 2017-02-09 | View |
Page 15447 of 17672, showing 5 records out of 88360 total, starting on record 77231, ending on 77235