NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84225 | CVE-2017-1170 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230. | 2 | 4.6 | Medium | 2017-07-18 | 2017-07-10 | View | |
84224 | CVE-2017-1161 | IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitrary commands on the system with the privileges of the www-data user. IBM X-Force ID: 122956. | 2 | 7.5 | High | 2017-04-27 | 2017-04-25 | View | |
84223 | CVE-2017-1160 | IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122892. | 2 | 3.5 | Low | 2017-04-27 | 2017-04-24 | View | |
84222 | CVE-2017-1154 | IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users. IBM Reference #: 1999892. | 2 | 4 | Medium | 2017-04-27 | 2017-04-04 | View | |
84221 | CVE-2017-1152 | IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293. | 2 | 4 | Medium | 2017-06-28 | 2017-06-23 | View |
Page 828 of 17672, showing 5 records out of 88360 total, starting on record 4136, ending on 4140