CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2016-3004

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the set of available applications.

    Published: 30 Nov 2016
    5.3
    Medium

    CVE-2016-5890

    Last Modified: 12 Apr 2025

    IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors.

    Published: 30 Nov 2016
    3.7
    Low

    CVE-2016-2952

    Last Modified: 12 Apr 2025

    IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.

    Published: 30 Nov 2016
    6.8
    Medium

    CVE-2016-2933

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request.

    Published: 30 Nov 2016
    5.3
    Medium

    CVE-2016-2935

    Last Modified: 12 Apr 2025

    The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.

    Published: 30 Nov 2016
    5.3
    Medium

    CVE-2016-2931

    Last Modified: 12 Apr 2025

    IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.

    Published: 30 Nov 2016
    5.3
    Medium

    CVE-2016-2932

    Last Modified: 12 Apr 2025

    IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.

    Published: 30 Nov 2016
    5.3
    Medium

    CVE-2016-2940

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.

    Published: 30 Nov 2016
    1.9
    Low

    CVE-2016-2943

    Last Modified: 12 Apr 2025

    IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.

    Published: 30 Nov 2016
    7.8
    High

    CVE-2016-2948

    Last Modified: 12 Apr 2025

    IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.

    Published: 30 Nov 2016
    3.3
    Low

    CVE-2016-2949

    Last Modified: 12 Apr 2025

    IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.

    Published: 30 Nov 2016
    6.5
    Medium

    CVE-2016-2950

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 30 Nov 2016
    3.7
    Low

    CVE-2016-2953

    Last Modified: 12 Apr 2025

    IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.

    Published: 30 Nov 2016
    4.3
    Medium

    CVE-2016-2957

    Last Modified: 12 Apr 2025

    IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.

    Published: 30 Nov 2016
    4.3
    Medium

    CVE-2016-2958

    Last Modified: 12 Apr 2025

    IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic" e-mail address in a response.

    Published: 30 Nov 2016
    8.8
    High

    CVE-2016-2963

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 30 Nov 2016
    2.1
    Low

    CVE-2016-3002

    Last Modified: 12 Apr 2025

    IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.

    Published: 30 Nov 2016
    3.5
    Low

    CVE-2016-3009

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page.

    Published: 30 Nov 2016
    6.1
    Medium

    CVE-2016-3057

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Nov 2016
    5.4
    Medium

    CVE-2016-5905

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 IF2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Nov 2016
    5.3
    Medium

    CVE-2016-5987

    Last Modified: 12 Apr 2025

    IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF3 allows remote attackers to obtain sensitive information via a crafted HTTP request that triggers construction of a runtime error message.

    Published: 30 Nov 2016
    7.5
    High

    CVE-2016-9564

    Last Modified: 12 Apr 2025

    Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only '/' and '.' characters.

    Published: 30 Nov 2016
    6.5
    Medium

    CVE-2016-2937

    Last Modified: 12 Apr 2025

    IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST request, related to an "untrusted information vulnerability."

    Published: 30 Nov 2016
    9.8
    Critical

    CVE-2016-2944

    Last Modified: 12 Apr 2025

    IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.

    Published: 30 Nov 2016
    5.4
    Medium

    CVE-2016-3014

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Quality Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Team Concert 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational DOORS Next Generation 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0986

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0989

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0992

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0993

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0994

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0995

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0999

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1000

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1019

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1022

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1060

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1063

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1068

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0987

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0988

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0991

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0997

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-0998

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1067

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1066

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1050

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1051

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1052

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1053

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016
    Unknown

    CVE-2017-1054

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

    Published: 30 Nov 2016