NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 81757 | CVE-2016-3043 | IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-13 | View | |
| 18937 | CVE-2016-3042 | Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients. | 2 | 3.5 | Low | 2017-01-19 | 2016-11-28 | View | |
| 18936 | CVE-2016-3040 | IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | 2 | 4.9 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 18935 | CVE-2016-3039 | IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2 | 8.5 | High | 2017-01-19 | 2016-11-28 | View | |
| 85295 | CVE-2016-3038 | IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114614. | 2 | 3.5 | Low | 2017-04-27 | 2017-04-21 | View |
Page 1967 of 17672, showing 5 records out of 88360 total, starting on record 9831, ending on 9835