NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81800 | CVE-2016-5958 | IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. | 2 | 5 | Medium | 2017-02-08 | 2017-02-07 | View | |
86819 | CVE-2016-5959 | IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136. | 2 | 5 | Medium | 2017-06-18 | 2017-06-13 | View | |
86820 | CVE-2016-5960 | IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171. | 2 | 2.1 | Low | 2017-06-18 | 2017-06-13 | View | |
21002 | CVE-2016-5963 | IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authenticated users to execute arbitrary code via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-19 | 2016-11-28 | View | |
81801 | CVE-2016-5964 | IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. | 2 | 5 | Medium | 2017-02-15 | 2017-02-13 | View |
Page 16189 of 17672, showing 5 records out of 88360 total, starting on record 80941, ending on 80945