PatchSiren

IBM CVE debriefs · Page 15

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL IBM CVE published 2017-02-08

CVE-2016-8954

CVE-2016-8954 is a critical authentication flaw in IBM dashDB Local where hard-coded credentials could let a remote attacker gain access to the Docker container or the database. NVD classifies the weakness as CWE-798 and assigns a CVSS 3.0 score of 9.8, reflecting unauthenticated network attack potential with high impact to confidentiality, integrity, and availability.

HIGH IBM CVE published 2017-02-08

CVE-2016-5934

CVE-2016-5934 describes a DLL search-order hijack issue in the IBM Tivoli Storage Manager FastBack installer. According to the published description, an attacker who can place a specially crafted DLL in the victim's path may cause the installer to run arbitrary code when it is executed. The NVD record rates the issue High with a CVSS 3.0 vector of AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H. This is primarily a s [truncated]

MEDIUM IBM CVE published 2017-02-08

CVE-2016-5918

CVE-2016-5918 is an information-disclosure flaw in IBM Tivoli Storage Manager HSM for Windows. When password access is set to prompt and the password is changed, the encrypted Tivoli Storage Manager password can appear in application trace output. The issue is rated medium severity and is primarily a confidentiality risk.

MEDIUM IBM CVE published 2017-02-08

CVE-2016-5902

CVE-2016-5902 is a cross-site scripting flaw in IBM Maximo Asset Management and related Maximo offerings. The issue allows arbitrary JavaScript to be embedded in the web UI, which can alter application behavior and may expose credentials or other session data within a trusted browser session. NVD rates the issue as medium severity, with network-based attack conditions but requiring user interaction.

MEDIUM IBM CVE published 2017-02-08

CVE-2016-5900

CVE-2016-5900 describes a sensitive-information disclosure issue in IBM Tealeaf Customer Experience on Cloud Network Capture Add-On. According to NVD, the flaw is caused by failure to properly validate the TLS certificate, which can let a remote attacker use man-in-the-middle techniques to obtain sensitive information. NVD rates the issue medium severity with CVSS 3.0 vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N.

MEDIUM IBM CVE published 2017-02-08

CVE-2016-0310

CVE-2016-0310 is an IBM Connections issue in which a maliciously influenced Host header can cause users to be navigated to an attacker-controlled domain. The public CVE record was published on 2017-02-08 and later modified on 2026-05-13. NVD lists IBM Connections 4.0, 4.5, 5.0, and 5.5 as vulnerable, with a medium-severity CVSS 3.0 vector that includes network access and user interaction.

MEDIUM IBM CVE published 2017-02-08

CVE-2016-0308

CVE-2016-0308 describes a link manipulation issue in IBM Connections 5.5 and earlier. The reported outcome is limited to the display of inappropriate background images, which points to a low-severity integrity/abuse problem rather than data theft or service disruption. NVD rates the issue CVSS 4.3 (MEDIUM) and maps it to CWE-284. IBM’s vendor advisory is the primary remediation reference in the supplied corpus.

MEDIUM IBM CVE published 2017-02-08

CVE-2016-0307

CVE-2016-0307 is a low-complexity information disclosure issue in IBM Connections. According to NVD, remote attackers can obtain sensitive information by reading stack traces returned in responses. The vulnerability affects IBM Connections 4.0, 4.5, 5.0, and 5.5, and IBM published vendor guidance and a patch reference alongside the public CVE record.

MEDIUM IBM CVE published 2017-02-08

CVE-2016-0305

CVE-2016-0305 is a cross-site scripting issue in IBM Connections. According to the NVD description, a remote attacker could use a specially crafted URL to execute script in a victim's browser in the context of the hosting website, which could expose cookie-based authentication credentials. NVD classifies the weakness as CWE-79 and rates the issue CVSS 5.4 (MEDIUM).

HIGH IBM CVE published 2017-02-08

CVE-2016-0214

CVE-2016-0214 is a HIGH-severity IBM vulnerability record tied to Tivoli Endpoint Manager / BigFix Platform. The published description says a remote attacker could upload arbitrary files, with execution only becoming likely if a victim is tricked into opening the uploaded file. For defenders, the main concern is unauthorized file placement on affected IBM management systems and any downstream risk if user [truncated]

MEDIUM IBM CVE published 2017-02-08

CVE-2016-0210

CVE-2016-0210 is an IBM Sterling B2B Integrator Standard Edition information-disclosure issue published by NVD on 2017-02-08. According to the supplied record, a remote attacker could send a specially crafted query to a vulnerable server that allows the HTTP OPTIONS method and cause sensitive information to be returned in the HTTP response. NVD rates the issue CVSS 5.3 (Medium), with network access, no pr [truncated]

LOW IBM CVE published 2017-02-08

CVE-2016-0206

CVE-2016-0206 is a low-severity availability issue in IBM Cloud Orchestrator. According to NVD, a local authenticated attacker can use a specially crafted, malformed URL to cause the server to slow down for a short period of time. The issue was published on 2017-02-08 and is mapped by NVD to IBM Cloud Orchestrator versions 2.3, 2.3.0.1, 2.4, 2.4.0.1, and 2.4.0.2.

MEDIUM IBM CVE published 2017-02-08

CVE-2016-0203

CVE-2016-0203 is an information disclosure issue in IBM Cloud Orchestrator’s task API. According to the NVD record, an authenticated user may be able to view background information associated with actions performed on virtual machines in projects where that user belongs. The issue was published on 2017-02-08 and is rated Medium severity with a CVSS 3.0 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.

LOW IBM CVE published 2017-02-08

CVE-2016-0202

CVE-2016-0202 is a low-severity information disclosure issue in IBM Cloud Orchestrator. According to the NVD description, an authenticated user could view any task in the current user’s domain through the application’s tasks backend object. The published CVSS 3.0 vector indicates low confidentiality impact with no integrity or availability impact.

LOW IBM CVE published 2017-02-08

CVE-2015-7494

CVE-2015-7494 is an authorization weakness in IBM Cloud Orchestrator services/[action]/launch API. According to IBM/NVD, an authenticated domain admin might be able to modify resources in another domain if they can obtain that other domain’s resource identifier. The issue was published on 2017-02-08 and is rated low severity (CVSS 2.8).

MEDIUM IBM CVE published 2017-02-08

CVE-2015-7493

IBM InfoSphere Information Server was reported vulnerable to a local command execution issue during installation under special circumstances. The impact described by NVD is exposure of sensitive information, and the issue is scoped to affected IBM InfoSphere Information Server releases rather than a network-facing remote exploit. IBM’s advisory is listed by NVD as the vendor patch reference.

MEDIUM IBM CVE published 2017-02-08

CVE-2015-7418

CVE-2015-7418 is an information disclosure issue in IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance. Sensitive data can linger in memory instead of being overwritten, which could let a local user with administrator privileges obtain confidential information.

MEDIUM IBM CVE published 2017-02-08

CVE-2015-1976

CVE-2015-1976 concerns IBM Security Directory Server and related Tivoli Directory Server versions where an authenticated user could execute commands into the web administration tool and cause it to crash. NVD rates the issue as medium severity with a local attack vector and high availability impact, so systems that expose the admin interface to authenticated users should be reviewed promptly.

MEDIUM IBM CVE published 2017-02-08

CVE-2017-1128

CVE-2017-1128 is a cross-site scripting vulnerability in IBM Rational DOORS Next Generation and related Rational Requirements Composer releases. The issue lets a user embed arbitrary JavaScript in the web UI, which can alter intended application behavior and may expose credentials within a trusted session. The record was published on 2017-02-08 and later modified in NVD without changing the original disclosure date.

MEDIUM IBM CVE published 2017-02-08

CVE-2017-1127

CVE-2017-1127 is a cross-site scripting vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0, with NVD CPE data also listing IBM Rational Requirements Composer 4.0 variants. The issue can let a user embed arbitrary JavaScript in the web UI, which may alter application behavior and expose credentials or other sensitive data within a trusted session. The NVD vector reflects a network-reacha [truncated]

MEDIUM IBM CVE published 2017-02-08

CVE-2016-9748

CVE-2016-9748 is an IBM information-disclosure issue in error response handling. According to NVD, sensitive information in error messages from IBM Rational DOORS Next Generation and IBM Rational Requirements Composer could help an attacker prepare further attacks against the system. The CVE was published on 2017-02-08; the 2026-05-13 modified timestamp reflects later record maintenance, not the original issue date.

MEDIUM IBM CVE published 2017-02-08

CVE-2016-6032

CVE-2016-6032 is a cross-site scripting vulnerability in IBM Rational Collaborative Lifecycle Management / Rational Team Concert Web UI. Affected versions are listed by NVD as 4.0.0 through 4.0.7, 5.0.0 through 5.0.2, and 6.0.0 through 6.0.3. The issue can let a user embed arbitrary JavaScript in the browser-based interface, which may alter application behavior and expose credentials within an authenticated session.

MEDIUM IBM CVE published 2017-02-08

CVE-2016-2866

CVE-2016-2866 is a medium-severity information disclosure issue in IBM Jazz Team Server. According to the NVD record, an authenticated user may be able to view some deployment information, which can expose limited environment details without affecting integrity or availability. The public record ties the issue to IBM Rational Collaborative Lifecycle Management releases 4.0.0 through 6.0.3 and points to an [truncated]

MEDIUM IBM CVE published 2017-02-08

CVE-2015-5013

IBM Security Access Manager appliances exposed configuration files that contained obfuscated plaintext passwords to authenticated users, creating an information-disclosure risk. The issue maps to CWE-522 and is scored medium severity because it requires local access and low privileges, but successful access could reveal sensitive credentials.

MEDIUM IBM CVE published 2017-02-08

CVE-2016-0270

CVE-2016-0270 covers an IBM Domino TLS AES-GCM issue in affected 9.0.1 release lines. Per NVD and the IBM PSIRT references, random nonce generation in AES-GCM could make it easier for a remote attacker to obtain an authentication key and spoof data by exploiting nonce reuse within a session and a "forbidden attack." The CVE is rated medium severity and is network-exploitable, but with high attack complexity.

HIGH IBM CVE published 2017-02-07

CVE-2016-6104

CVE-2016-6104 is an IBM key lifecycle manager file-upload vulnerability that could let a remote attacker upload arbitrary files and potentially execute arbitrary code on the affected system. The issue was publicly disclosed on 2017-02-07 and is rated HIGH in NVD with a CVSS 3.0 score of 7.2.

MEDIUM IBM CVE published 2017-02-07

CVE-2016-6097

CVE-2016-6097 is a local information-disclosure issue in IBM Tivoli Key Lifecycle Manager and related IBM Security Key Lifecycle Manager releases. According to NVD, a local attacker on the same system could read web pages stored locally by the application, exposing information without requiring privileges or user interaction. The issue is rated Medium by NVD and maps to CWE-200 (Exposure of Sensitive Info [truncated]

MEDIUM IBM CVE published 2017-02-07

CVE-2016-6096

CVE-2016-6096 is a cross-site scripting vulnerability in IBM Tivoli Key Lifecycle Manager. According to the NVD record and the vendor reference it cites, affected users can embed arbitrary JavaScript in the Web UI, which can alter intended functionality and may lead to credential disclosure within a trusted session. NVD published the record on 2017-02-07 and later modified it on 2026-05-13.

MEDIUM IBM CVE published 2017-02-07

CVE-2016-6094

CVE-2016-6094 is an information-disclosure issue in IBM Tivoli Key Lifecycle Manager / IBM Security Key Lifecycle Manager. The vulnerable software can generate an error message that reveals sensitive information about the environment, users, or associated data. NVD assigns CWE-200 and a CVSS 3.0 score of 4.3 (Medium), reflecting a network-reachable issue with low complexity, no user interaction, and confi [truncated]

MEDIUM IBM CVE published 2017-02-07

CVE-2016-6092

CVE-2016-6092 describes a cleartext credential storage issue in IBM Key Lifecycle Manager products. According to the NVD record, affected versions include IBM Tivoli Key Lifecycle Manager 2.0.1.x and IBM Security Key Lifecycle Manager 2.5.x and 2.6.x. Because the credentials can be read by a local user, the main risk is unauthorized disclosure of sensitive authentication data, which can be reused to acces [truncated]