NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 82275 | CVE-2015-5013 | The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access. | 2 | 2.1 | Low | 2017-02-15 | 2017-02-14 | View | |
| 26306 | CVE-2015-5012 | The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-03-11 | View | |
| 26305 | CVE-2015-5011 | IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command. | 2 | 3.2 | Low | 2017-01-19 | 2015-10-26 | View | |
| 26304 | CVE-2015-5010 | IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack. | 2 | 5 | Medium | 2017-01-19 | 2016-03-10 | View | |
| 26303 | CVE-2015-5009 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through 8, and 8.0 before 8.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-07 | View |
Page 3096 of 17672, showing 5 records out of 88360 total, starting on record 15476, ending on 15480