PatchSiren

IBM CVE debriefs · Page 14

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH IBM CVE published 2017-03-01

CVE-2016-9993

CVE-2016-9993 is a SQL injection vulnerability in IBM Kenexa LCMS Premier on Cloud. According to NVD, affected versions include 9.0 through 10.2, and the issue is rated CVSS 3.0 7.1 (High). A remote attacker with low privileges could send crafted SQL statements and potentially read, add, modify, or delete backend database information.

HIGH IBM CVE published 2017-03-01

CVE-2016-9992

CVE-2016-9992 is a SQL injection vulnerability in IBM Kenexa LCMS Premier on Cloud. NVD rates it High (CVSS 7.1) and maps it to CWE-89. A remote attacker with low privileges could submit crafted SQL input to read, add, modify, or delete backend database information. NVD’s vulnerable CPEs cover Kenexa LCMS Premier versions 9.0 through 9.5 and 10.0 through 10.2.

MEDIUM IBM CVE published 2017-03-01

CVE-2016-8232

CVE-2016-8232 is a DOM-based cross-site scripting issue in the Advanced Management Module (AMM) used by Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, and HX5 systems. According to the NVD record, the issue was publicly disclosed on 2017-03-01 and affects AMM versions earlier than 66Z. A crafted URL sent to the AMM can lead to script execution in a user’s browser and exposure of AMM data such as cookies [truncated]

MEDIUM IBM CVE published 2017-03-01

CVE-2016-5932

CVE-2016-5932 is a cross-site scripting vulnerability in IBM Connections 4.0, 4.5, 5.0, and 5.5. IBM and NVD describe the issue as allowing users to embed arbitrary JavaScript code in the Web UI, which can alter intended functionality and may lead to credentials disclosure within a trusted session. The CVE was published on 2017-03-01 and later modified on 2026-05-13 in NVD metadata.

HIGH IBM CVE published 2017-03-01

CVE-2016-2880

IBM QRadar 7.2 contains a local credential-protection flaw: the encryption key used to encrypt the service account password is stored in a way that a local user can obtain. NVD classifies the issue as high severity (CVSS 3.0: 7.8) and maps it to CWE-320. The vulnerable versions listed in the supplied corpus are QRadar 7.2.0 through 7.2.7. IBM’s advisory is referenced in the record, indicating vendor remed [truncated]

HIGH IBM CVE published 2017-03-01

CVE-2016-2879

CVE-2016-2879 is a high-severity IBM QRadar 7.2 issue involving outdated hashing of certain passwords. According to the NVD record and IBM’s advisory reference, a local user with limited privileges could obtain and decrypt user credentials. The affected range listed by NVD covers QRadar Security Information and Event Manager 7.2.0 through 7.2.7. IBM references this as security advisory 1997341.

HIGH IBM CVE published 2017-02-24

CVE-2016-9975

CVE-2016-9975 is a cross-site request forgery (CSRF) flaw reported in IBM Jazz for Service Management. In practical terms, a malicious site could try to induce a logged-in user’s browser to send unauthorized requests to an IBM web application that trusts that user. The NVD record rates the issue CVSS 8.8 (HIGH) with network attack vector and user interaction required.

LOW IBM CVE published 2017-02-24

CVE-2016-9009

CVE-2016-9009 is a low-severity IBM WebSphere MQ 8.0 vulnerability that can let an authenticated user with authority to create a cluster object cause a denial of service to MQ clustering. The published NVD record assigns a CVSS 3.0 base score of 3.1 (AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L), indicating limited impact but a real availability risk for clustered MQ deployments.

HIGH IBM CVE published 2017-02-24

CVE-2016-8998

CVE-2016-8998 describes a buffer overflow issue in IBM Tivoli Storage Manager Server 7.1. According to NVD and IBM’s referenced advisory, an authenticated user with TSM administrator privileges could use a specially crafted SQL query to trigger the flaw and potentially execute arbitrary code on the server. NVD classifies the weakness as CWE-119 and assigns a high-severity CVSS 3.0 score of 7.2.

HIGH IBM CVE published 2017-02-23

CVE-2016-8974

CVE-2016-8974 is an XML External Entity (XXE) flaw in IBM Rational Rhapsody Design Manager that can be triggered when processing XML data. IBM’s advisory, referenced by NVD, indicates the issue can expose highly sensitive information or consume available memory, creating a denial-of-service condition. NVD classifies the weakness as CWE-611 and rates the issue High severity.

MEDIUM IBM CVE published 2017-02-23

CVE-2016-6055

CVE-2016-6055 is a cross-site scripting issue in IBM Rational DOORS Next Generation, with IBM describing impact to 4.0, 5.0, and 6.0. The flaw can let users embed arbitrary JavaScript in the Web UI, changing application behavior and potentially exposing credentials within a trusted session. NVD classifies it as CWE-79 with CVSS 3.0 vector AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N, which is consistent with a use [truncated]

MEDIUM IBM CVE published 2017-02-23

CVE-2016-5883

CVE-2016-5883 describes a cross-site scripting issue in IBM iNotes 8.5 and 9.0. According to the NVD record, the flaw allows arbitrary JavaScript to be embedded in the web UI, which can alter intended application behavior and may lead to credential disclosure within a trusted session. The issue was published on 2017-02-23 and later updated in the NVD record on 2026-05-13; those dates describe record lifec [truncated]

MEDIUM IBM CVE published 2017-02-22

CVE-2016-8986

CVE-2016-8986 describes an IBM WebSphere MQ 8.0 issue where an authenticated user with access to the queue manager can use specially crafted HTTP requests to bring down MQ channels. IBM’s advisory/reference 1998648 is cited in the official NVD record. The issue is rated CVSS 6.5 (Medium) with a primary impact on availability.

MEDIUM IBM CVE published 2017-02-22

CVE-2016-8915

CVE-2016-8915 is an IBM WebSphere MQ 8.0 availability issue in which an authenticated user with access to the queue manager and queue may be able to deny service to other channels running under the same process. NVD maps the issue to CWE-284 and rates it CVSS 3.0 6.5 (medium), reflecting network reachability, low complexity, and required privileges with a high availability impact. NVD also lists affected [truncated]

MEDIUM IBM CVE published 2017-02-22

CVE-2016-3052

CVE-2016-3052 describes a confidentiality issue in IBM WebSphere MQ where, under non-standard configurations, password data may be transmitted in clear text over the network. If an attacker can observe or intercept that traffic, the password could be exposed through man-in-the-middle techniques. NVD rates the issue CVSS 3.0 5.9 (Medium) and lists affected WebSphere MQ versions through 8.0.0.5.

MEDIUM IBM CVE published 2017-02-22

CVE-2016-3013

CVE-2016-3013 is an IBM WebSphere MQ 8.0 availability issue where an authenticated user could crash an MQ channel due to improper data conversion handling. NVD rates the issue medium severity and lists affected versions up to 8.0.0.5. IBM’s advisory reference is available, and the record does not indicate known ransomware use or KEV inclusion.

MEDIUM IBM CVE published 2017-02-16

CVE-2016-6062

CVE-2016-6062 is a cross-site scripting issue in IBM Resilient v26.0, v26.1, and v26.2. According to the CVE record, the flaw allows arbitrary JavaScript to be embedded in the Web UI, which can alter intended application behavior and potentially expose credentials within a trusted session. The NVD rates the issue as medium severity (CVSS 3.0: 6.1), with network access required and user interaction needed. [truncated]

HIGH IBM CVE published 2017-02-16

CVE-2016-5919

CVE-2016-5919 is a weak-cryptography issue in IBM Security Access Manager for Web. According to the NVD record and IBM’s advisory reference, affected releases include 7.0.0, 8.0.0, and 9.0.0, and the flaw could allow an attacker to decrypt highly sensitive information. The NVD rates the issue at CVSS 7.5 (HIGH), with network attack vector, no privileges required, and high confidentiality impact.

CRITICAL IBM CVE published 2017-02-15

CVE-2016-9706

CVE-2016-9706 is a critical IBM XML processing issue in SOAP flows that can be triggered remotely without authentication or user interaction. NVD describes the flaw as an XML External Entity (XXE) injection weakness that can lead to denial of service, sensitive information exposure, or memory exhaustion in IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker 8.0.

MEDIUM IBM CVE published 2017-02-15

CVE-2016-9010

CVE-2016-9010 describes a remotely exploitable click hijacking issue in IBM message broker products. A victim can be lured to a malicious website, where the attacker may hijack click actions and potentially drive further attacks. The CVE was published on 2017-02-15 and NVD lists it as Modified on 2026-05-13.

HIGH IBM CVE published 2017-02-15

CVE-2016-8972

CVE-2016-8972 is a local privilege-escalation issue in IBM AIX bellmail that could allow a local user to gain root privileges by using a specially crafted command. IBM’s advisory references APARs IV91006, IV91007, IV91008, IV91010, and IV91011. NVD published the record on 2017-02-15 and rates it High severity (CVSS 7.8).

MEDIUM IBM CVE published 2017-02-15

CVE-2016-8968

CVE-2016-8968 is a cross-site scripting issue in IBM Jazz Foundation. According to the NVD record and IBM’s advisory reference, a user can embed arbitrary JavaScript in the Web UI, altering intended functionality and potentially disclosing credentials within a trusted session. The issue is rated medium severity and was published on 2017-02-15.

MEDIUM IBM CVE published 2017-02-15

CVE-2016-8944

CVE-2016-8944 is a medium-severity IBM AIX issue that can let a local user trigger a system crash by opening a file with a specially crafted argument. The public record ties the issue to AIX 7.1 and 7.2 and points to IBM PSIRT guidance and APARs for remediation.

HIGH IBM CVE published 2017-02-15

CVE-2016-6079

CVE-2016-6079 is a high-severity IBM AIX vulnerability that can let a locally authenticated user obtain root-level privileges. The CVE description names AIX 5.3, 6.1, 7.1, and 7.2, and the NVD record also maps the issue to multiple IBM VIOS 2.2.x releases. Because exploitation requires local authentication, this is most urgent on systems with shared access, administrative tooling, or any environment where [truncated]

MEDIUM IBM CVE published 2017-02-15

CVE-2016-6077

CVE-2016-6077 covers a command-execution issue in IBM Cognos Disclosure Management 10.2. According to the CVE/NVD metadata, a malicious attacker could execute commands as a lower-privileged user when that user opens a malicious document. The CVE was published on 2017-02-15. NVD lists affected versions from 10.2.0 through 10.2.6 and assigns a medium severity score.

MEDIUM IBM CVE published 2017-02-15

CVE-2016-6060

CVE-2016-6060 is an information disclosure issue in IBM Rational DOORS Next Generation and related IBM Rational Requirements Composer releases. A JazzGuest user could view project names, which can reveal sensitive project metadata even though the issue does not affect integrity or availability.

HIGH IBM CVE published 2017-02-15

CVE-2016-6033

CVE-2016-6033 is a cross-site request forgery (CSRF) vulnerability affecting IBM VMware-related storage management products. The NVD entry rates it High and ties it to user interaction in a network-reachable attack path, meaning a trusted authenticated user can be induced to send unauthorized actions through the web interface.

CRITICAL IBM CVE published 2017-02-15

CVE-2016-0360

CVE-2016-0360 is a critical deserialization vulnerability in IBM WebSphere MQ JMS client versions 7.0.1, 7.1, 7.5, 8.0, and 9.0. IBM and NVD describe client classes that deserialize objects from untrusted sources, which could allow arbitrary Java code execution when vulnerable classes are present on the classpath.

MEDIUM IBM CVE published 2017-02-13

CVE-2017-1121

CVE-2017-1121 is a medium-severity cross-site scripting flaw in IBM WebSphere Application Server. IBM and NVD describe affected versions as 7.0, 8.0, 8.5, 8.5.5, and 9.0. The issue can let a user embed arbitrary JavaScript in the Web UI, which may alter intended functionality and potentially expose credentials within a trusted session.

CRITICAL IBM CVE published 2017-02-08

CVE-2016-9005

CVE-2016-9005 is a critical IBM System Storage TS3100-TS3200 Tape Library vulnerability that, according to the CVE/NVD record, could allow an unauthenticated user with access to the company network to change a user's password and gain remote access to the system. NVD rates the issue CVSS 3.0 9.8 (Critical) and maps it to CWE-284 (Improper Access Control).