NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85372 | CVE-2017-2090 | Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors. | 2 | 4 | Medium | 2017-05-07 | 2017-05-05 | View | |
87890 | CVE-2017-1398 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 127385. | 2 | 5.8 | Medium | 2017-07-18 | 2017-07-17 | View | |
86922 | CVE-2017-1379 | IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Portal. IBM X-Force ID: 127002. | 2 | 5 | Medium | 2017-06-23 | 2017-06-22 | View | |
87357 | CVE-2017-1349 | IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM X-Force ID: 126525. | 2 | 2.1 | Low | 2017-06-28 | 2017-06-27 | View | |
87356 | CVE-2017-1348 | IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126524. | 2 | 3.5 | Low | 2017-06-28 | 2017-06-26 | View |
Page 766 of 17672, showing 5 records out of 88360 total, starting on record 3826, ending on 3830