CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2015-7426

    Last Modified: 12 Apr 2025

    The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 2 Jan 2016
    8.4
    High

    CVE-2015-7430

    Last Modified: 12 Apr 2025

    The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to read or write to arbitrary GPFS data via unspecified vectors.

    Published: 2 Jan 2016
    6.1
    Medium

    CVE-2015-7431

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 2 Jan 2016
    4.7
    Medium

    CVE-2015-7438

    Last Modified: 12 Apr 2025

    IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive cleartext web-services information by leveraging database access.

    Published: 2 Jan 2016
    4.3
    Medium

    CVE-2015-7452

    Last Modified: 12 Apr 2025

    IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.

    Published: 2 Jan 2016
    8.5
    High

    CVE-2015-7429

    Last Modified: 12 Apr 2025

    The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.4 allows remote authenticated users to restore arbitrary virtual machines and consequently obtain sensitive information by visiting the vSphere inventory.

    Published: 2 Jan 2016
    3.7
    Low

    CVE-2015-4989

    Last Modified: 12 Apr 2025

    The portal in IBM Tealeaf Customer Experience before 8.7.1.8814, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows remote attackers to read arbitrary charts by specifying an internal chart name.

    Published: 2 Jan 2016
    4
    Medium

    CVE-2015-4990

    Last Modified: 12 Apr 2025

    The portal in IBM Tealeaf Customer Experience before 8.7.1.8818, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows local users to discover credentials by leveraging privileges during an unspecified connection type.

    Published: 2 Jan 2016
    5.1
    Medium

    CVE-2015-4996

    Last Modified: 12 Apr 2025

    IBM Rational ClearQuest 7.1.x and 8.0.0.x before 8.0.0.17 and 8.0.1.x before 8.0.1.10 allows local users to spoof database servers and discover credentials via unspecified vectors.

    Published: 2 Jan 2016
    8
    High

    CVE-2015-5018

    Last Modified: 12 Apr 2025

    IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticated users to execute arbitrary OS commands by leveraging Local Management Interface (LMI) access.

    Published: 2 Jan 2016
    4.3
    Medium

    CVE-2015-5020

    Last Modified: 12 Apr 2025

    The Big SQL component in IBM InfoSphere BigInsights 3.0, 3.0.0.1, 3.0.0.2, and 4.0 allows remote authenticated users to bypass intended access restrictions and truncate arbitrary tables via unspecified vectors.

    Published: 2 Jan 2016
    7
    High

    CVE-2015-7442

    Last Modified: 12 Apr 2025

    consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value.

    Published: 2 Jan 2016
    5.4
    Medium

    CVE-2015-7402

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 2 Jan 2016
    5.4
    Medium

    CVE-2015-7451

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 2 Jan 2016
    5.4
    Medium

    CVE-2015-7409

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.6 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified field.

    Published: 1 Jan 2016
    6.5
    Medium

    CVE-2015-7456

    Last Modified: 12 Apr 2025

    IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows remote authenticated users to discover object-storage admin passwords via unspecified vectors.

    Published: 1 Jan 2016
    3.7
    Low

    CVE-2015-7420

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in GSKit on IBM MQ M2000 appliances before 8.0.0.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2015-7421.

    Published: 1 Jan 2016
    4.3
    Medium

    CVE-2015-7445

    Last Modified: 12 Apr 2025

    IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.x before 1.0.0.4, when guest access is configured, allow remote authenticated users to obtain sensitive information by reading error messages in responses.

    Published: 1 Jan 2016
    5.3
    Medium

    CVE-2015-4941

    Last Modified: 12 Apr 2025

    IBM WebSphere MQ Light 1.x before 1.0.2 mishandles abbreviated TLS handshakes, which allows remote attackers to cause a denial of service (MQXR service crash) via unspecified vectors.

    Published: 1 Jan 2016
    5.3
    Medium

    CVE-2015-4943

    Last Modified: 12 Apr 2025

    IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4942.

    Published: 1 Jan 2016
    5.4
    Medium

    CVE-2015-5049

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 1 Jan 2016
    3.7
    Low

    CVE-2015-7421

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in GSKit on IBM MQ M2000 appliances before 8.0.0.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2015-7420.

    Published: 1 Jan 2016
    7.4
    High

    CVE-2015-7410

    Last Modified: 12 Apr 2025

    The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.

    Published: 1 Jan 2016
    5.4
    Medium

    CVE-2015-7415

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 1 Jan 2016
    6.8
    Medium

    CVE-2015-7441

    Last Modified: 12 Apr 2025

    Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.2 does not properly use SSL for its HTTPS connection, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

    Published: 1 Jan 2016
    3.3
    Low

    CVE-2015-6644

    Last Modified: 12 Apr 2025

    Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.

    Published: 1 Jan 2016
    7.8
    High

    CVE-2015-7489

    Last Modified: 12 Apr 2025

    IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users to gain privileges by modifying a script.

    Published: 1 Jan 2016
    7.4
    High

    CVE-2015-1947

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in IBM InfoSphere BigInsights 3.0, 3.0.0.1, 3.0.0.2, and 4.0, when a DB2 database is used, allows local users to gain privileges via a Trojan horse library that is loaded by a setuid or setgid program.

    Published: 31 Dec 2015
    8.6
    High

    CVE-2015-5987

    Last Modified: 12 Apr 2025

    Belkin F9K1102 2 devices with firmware 2.10.17 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.

    Published: 31 Dec 2015
    9.8
    Critical

    CVE-2015-5988

    Last Modified: 12 Apr 2025

    The web management interface on Belkin F9K1102 2 devices with firmware 2.10.17 has a blank password, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.

    Published: 31 Dec 2015
    9.8
    Critical

    CVE-2015-5989

    Last Modified: 12 Apr 2025

    Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain administrative privileges via certain changes to LockStatus and Login_Success values.

    Published: 31 Dec 2015
    8.8
    High

    CVE-2015-5990

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Belkin F9K1102 2 devices with firmware 2.10.17 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 31 Dec 2015
    9.8
    Critical

    CVE-2015-2874

    Last Modified: 12 Apr 2025

    Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.

    Published: 31 Dec 2015
    7.5
    High

    CVE-2015-2875

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to read arbitrary files via a full pathname in a download request during a Wi-Fi session.

    Published: 31 Dec 2015
    8.8
    High

    CVE-2015-2876

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session.

    Published: 31 Dec 2015
    5.3
    Medium

    CVE-2015-2894

    Last Modified: 12 Apr 2025

    Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a denial of service (application crash) via format string specifiers.

    Published: 31 Dec 2015
    7.3
    High

    CVE-2015-2895

    Last Modified: 12 Apr 2025

    Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via long command input.

    Published: 31 Dec 2015
    5.3
    Medium

    CVE-2015-2896

    Last Modified: 12 Apr 2025

    The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, and event-log information via a command.

    Published: 31 Dec 2015
    8.8
    High

    CVE-2015-2912

    Last Modified: 12 Apr 2025

    The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted HTTP request.

    Published: 31 Dec 2015
    5.9
    Medium

    CVE-2015-2913

    Last Modified: 12 Apr 2025

    server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values, which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.

    Published: 31 Dec 2015
    6.1
    Medium

    CVE-2015-2918

    Last Modified: 12 Apr 2025

    The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

    Published: 31 Dec 2015
    6.8
    Medium

    CVE-2015-5994

    Last Modified: 12 Apr 2025

    The web management interface on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 has a default password of admin for the admin account and a default password of password for the medialink account, which allows remote attackers to obtain administrative privileges by leveraging a Wi-Fi session.

    Published: 31 Dec 2015
    9.8
    Critical

    CVE-2015-6018

    Last Modified: 12 Apr 2025

    The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.

    Published: 31 Dec 2015
    9.8
    Critical

    CVE-2015-7277

    Last Modified: 12 Apr 2025

    The web administration interface on Amped Wireless R10000 devices with firmware 2.5.2.11 has a default password of admin for the admin account, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.

    Published: 31 Dec 2015
    8
    High

    CVE-2015-7284

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 31 Dec 2015
    9.8
    Critical

    CVE-2015-5995

    Last Modified: 12 Apr 2025

    Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header.

    Published: 31 Dec 2015
    8.5
    High

    CVE-2015-6019

    Last Modified: 12 Apr 2025

    The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.

    Published: 31 Dec 2015
    8.8
    High

    CVE-2015-7278

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Amped Wireless R10000 devices with firmware 2.5.2.11 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 31 Dec 2015
    7.5
    High

    CVE-2014-3260

    Last Modified: 12 Apr 2025

    Pacom 1000 CCU and RTU GMS devices allow remote attackers to spoof the controller-to-base data stream by leveraging improper use of cryptography.

    Published: 31 Dec 2015
    3.7
    Low

    CVE-2014-4876

    Last Modified: 12 Apr 2025

    Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.

    Published: 31 Dec 2015