NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84225  CVE-2017-1170  IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230.    4.6  Medium  2017-07-18  2017-07-10  View
84224  CVE-2017-1161  IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitrary commands on the system with the privileges of the www-data user. IBM X-Force ID: 122956.    7.5  High  2017-04-27  2017-04-25  View
84223  CVE-2017-1160  IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122892.    3.5  Low  2017-04-27  2017-04-24  View
84222  CVE-2017-1154  IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users. IBM Reference #: 1999892.    Medium  2017-04-27  2017-04-04  View
84221  CVE-2017-1152  IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.    Medium  2017-06-28  2017-06-23  View

Page 828 of 17672, showing 5 records out of 88360 total, starting on record 4136, ending on 4140

Actions