NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85295 | CVE-2016-3038 | IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114614. | 2 | 3.5 | Low | 2017-04-27 | 2017-04-21 | View | |
18935 | CVE-2016-3039 | IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2 | 8.5 | High | 2017-01-19 | 2016-11-28 | View | |
18936 | CVE-2016-3040 | IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | 2 | 4.9 | Medium | 2017-01-19 | 2016-11-28 | View | |
18937 | CVE-2016-3042 | Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients. | 2 | 3.5 | Low | 2017-01-19 | 2016-11-28 | View | |
81757 | CVE-2016-3043 | IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-13 | View |
Page 15706 of 17672, showing 5 records out of 88360 total, starting on record 78526, ending on 78530