NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 16788 | CVE-2016-0353 | IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 16787 | CVE-2016-0350 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0313. | 2 | 3.5 | Low | 2017-01-19 | 2016-07-08 | View | |
| 16786 | CVE-2016-0349 | IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call. | 2 | 4 | Medium | 2017-01-19 | 2016-11-29 | View | |
| 16785 | CVE-2016-0346 | Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | 2 | 3.5 | Low | 2017-01-19 | 2016-11-28 | View | |
| 16784 | CVE-2016-0341 | IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing the network. | 2 | 5 | Medium | 2017-01-19 | 2016-05-19 | View |
Page 2469 of 17672, showing 5 records out of 88360 total, starting on record 12341, ending on 12345