NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
18870  CVE-2016-2912  Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.    3.5  Low  2017-01-19  2016-11-28  View
18871  CVE-2016-2914  Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension.    5.5  Medium  2017-01-19  2016-11-28  View
18872  CVE-2016-2917  The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gain privileges, via unspecified vectors.    6.5  Medium  2017-01-19  2016-12-01  View
18873  CVE-2016-2923  IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JAX-RS API cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.    Medium  2017-01-19  2016-11-28  View
81738  CVE-2016-2924  IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim"s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim"s cookie-based authentication credentials.    3.5  Low  2017-02-15  2017-02-15  View

Page 15688 of 17672, showing 5 records out of 88360 total, starting on record 78436, ending on 78440

Actions