These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2016-3020 is a medium-severity IBM Security Access Manager for Web issue involving improper content validation. Affected deployments can allow security restrictions to be bypassed and malicious content to be loaded after a victim opens specially crafted content.
CVE-2017-1093 describes a local privilege-escalation issue in IBM AIX’s bellmail binary. IBM and NVD identify affected AIX releases as 6.1, 7.1, and 7.2, with impact sufficient to allow a local user to gain root privileges.
CVE-2016-6116 affects IBM Tivoli Key Lifecycle Manager 2.5 and 2.6. Because HTTP Strict Transport Security was not properly enabled, a remote attacker with a man-in-the-middle position could potentially expose sensitive information. The issue is categorized as information disclosure rather than code execution, but it still matters because it can weaken transport protections for web sessions and administrative access.
CVE-2016-6103 is a cross-site request forgery (CSRF) vulnerability in IBM Tivoli Key Lifecycle Manager 2.5 and 2.6. The issue could let an attacker cause a trusted user’s browser session to submit unauthorized actions to the application. NVD rates the issue as high severity, with network access and user interaction required.
CVE-2016-6099 is a medium-severity information disclosure issue in IBM Tivoli Key Lifecycle Manager 2.5 and 2.6. IBM and NVD describe the flaw as exposing sensitive information to unauthorized users, which could help attackers plan or carry out follow-on activity against the system. The NVD record assigns a CVSS 3.0 score of 5.3 with a network-based, low-complexity attack path and no privileges or user in [truncated]
CVE-2016-6095 describes an authentication weakness in IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 where inadequate account lockout settings could let a remote attacker brute-force credentials. NVD rates the issue critical with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a network-reachable attack surface with severe impact if login protections are bypassed.
CVE-2016-5935 is an IBM information-disclosure issue tied to improper SSL certificate validation in Jazz for Service Management-related components. A remote attacker positioned for man-in-the-middle interception could potentially read sensitive information in transit. NVD rates the issue Medium (5.9) with network access required but high attack complexity.
CVE-2016-9739 is a credential exposure issue in IBM Security Identity Manager Virtual Appliance. According to NVD, user credentials were stored in plain text and could be read by a local user. The issue was publicly disclosed on 2017-02-01 and affects multiple IBM Security Identity Manager 7.x releases listed by NVD.
CVE-2016-9704 is a cross-site scripting (XSS) vulnerability in IBM Security Identity Manager Virtual Appliance. NVD describes it as allowing users to embed arbitrary JavaScript in the Web UI, which can alter application behavior and may expose credentials within a trusted session. The issue was published on 2017-02-01 and NVD later marked the record as modified on 2026-05-13.
CVE-2016-9703 is a low-severity IBM Security Identity Manager Virtual Appliance issue in which session tokens are not invalidated properly. According to the CVE/NVD record, an unauthorized user with physical access to the workstation could use that weakness to obtain sensitive information. The vulnerable IBM Security Identity Manager Virtual Appliance versions listed by NVD span 7.0.0.0 through 7.0.1.4.
CVE-2016-9008 is a high-severity access-control issue in IBM UrbanCode Deploy. NVD and IBM’s referenced advisory identify affected releases across the 6.0, 6.1, and 6.2 lines up to 6.2.2.1. The flaw could allow a malicious user to reach the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.
CVE-2016-9000 is a medium-severity browser-side weakness in IBM InfoSphere DataStage. IBM and NVD describe it as insufficient HTML iframe protection that can let a remote attacker steer a user to attacker-controlled content through a specially crafted URL. The practical impact is mainly client-side: clickjacking or related browser attacks, not server takeover. NVD published the record on 2017-02-01 and la [truncated]
CVE-2016-8999 is a medium-severity IBM InfoSphere issue involving path-relative stylesheet imports. According to NVD, the flaw can cause a page to render in quirks mode, which can then facilitate malicious CSS injection. The affected surface is web-facing and requires user interaction, so the main risk is UI tampering and related integrity impact rather than direct code execution.
CVE-2016-8982 is an information disclosure issue in IBM InfoSphere Information Server. According to the published description, sensitive information was stored in URL parameters, which could expose it to unauthorized parties through server logs, the referrer header, or browser history. NVD classifies the weakness as CWE-200 and assigns a CVSS 3.0 score of 5.3 (Medium).
CVE-2016-8977 is a medium-severity information disclosure issue affecting IBM BigFix Inventory v9 and IBM License Metric Tool 9.2.0. According to the NVD record, an unauthorized user could obtain sensitive information through HTTP GET requests, which could then support follow-on attacks.
CVE-2016-8963 is a local information-disclosure issue in IBM BigFix Inventory v9. According to NVD, the product can store potentially sensitive information in log files that may be readable by a local user. The CVSS v3.0 vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, which aligns with a confidentiality-focused impact rather than code execution or service disruption.
CVE-2016-8938 is a critical IBM UrbanCode Deploy vulnerability in which a specially crafted file upload could replace code on the server, enabling code execution on UCD agent machines that host customer production applications. NVD published the record on 2017-02-01 and later marked it modified on 2026-05-13; the IBM vendor advisory is referenced in the NVD record.
CVE-2016-8933 is a directory traversal issue in IBM Kenexa LMS on Cloud. According to the NVD record, a remote attacker could send a specially crafted URL containing dot-dot sequences ("/../") to view arbitrary files on the system. The issue was publicly disclosed in the NVD record on 2017-02-01 and later modified on 2026-05-13.
CVE-2016-8932 describes an IBM Kenexa LMS on Cloud flaw where arbitrary file upload could enable code execution on the vulnerable server. NVD rates the issue high severity (CVSS 8.8) with network access, low attack complexity, and low privileges required. The affected product versions listed by NVD are IBM Kenexa LMS 4.1, 4.2, 4.2.2, 4.2.3, 4.2.4, 5.0, 5.1, and 5.2. IBM published a vendor advisory and pat [truncated]
CVE-2016-8931 is a high-severity IBM Kenexa LMS on Cloud vulnerability published on 2017-02-01. NVD describes it as an arbitrary file upload issue that could let a remote attacker execute code on the server. The record maps the flaw to CWE-284 and assigns a CVSS 3.0 score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2016-8930 is a SQL injection vulnerability in IBM Kenexa LMS on Cloud. According to the NVD record, affected releases include Kenexa LMS 4.1, 4.2, 4.2.2, 4.2.3, 4.2.4, 5.0, 5.1, and 5.2. A remote attacker who can reach the vulnerable application and submit crafted input may be able to access or alter backend database content. The CVSS 3.0 vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L, which indicates [truncated]
CVE-2016-8929 is a medium-severity SQL injection issue in IBM Kenexa LMS on Cloud. According to NVD, the flaw can let an attacker influence back-end database operations and potentially view, add, modify, or delete data. The NVD record maps the issue to CWE-89 and lists multiple affected IBM Kenexa LMS versions. IBM vendor guidance is referenced in the NVD record.
CVE-2016-8928 is a high-severity SQL injection vulnerability in IBM Kenexa LMS on Cloud. NVD classifies it as CWE-89 and lists affected Kenexa LMS versions including 4.1, 4.2, 4.2.2, 4.2.3, 4.2.4, 5.0, 5.1, and 5.2. A remote attacker with low privileges could send specially crafted SQL statements to affect data stored in the backend database.
CVE-2016-8919 is a high-severity denial-of-service vulnerability in IBM WebSphere Application Server. According to the published description, the issue involves allowing serialized objects from untrusted sources to run in a way that can consume resources. The impact is availability-only: no confidentiality or integrity impact is indicated in the CVSS vector, but the availability impact is rated high.
CVE-2016-6115 is a buffer overflow in IBM General Parallel File System / IBM Spectrum Scale. According to NVD, a remote authenticated attacker with high privileges could overflow a buffer and potentially execute arbitrary code on the system with root privileges, or cause the server to crash. The issue was published on 2017-02-01 and is rated HIGH severity.
CVE-2016-6110 describes a credential-disclosure issue in IBM Tivoli Storage Manager and IBM Tivoli Storage Manager for Virtual Environments Data Protection for VMware. According to NVD, a local user could obtain unencrypted login credentials for VMware vCenter. The issue is scored medium overall, with high confidentiality impact and no direct integrity or availability impact.
CVE-2016-6068 is an IBM UrbanCode Deploy information disclosure issue. According to NVD, an authenticated user with access to the product’s REST endpoints could access API and CLI getResource secured role properties. IBM and NVD published the record on 2017-02-01; the NVD entry was later modified on 2026-05-13, but that does not change the original disclosure timing.
CVE-2016-6001 is a low-severity server-side request forgery (SSRF) issue in IBM Forms Experience Builder. According to NVD, the flaw can be triggered from the application design interface and may allow limited disclosure of internal resources. IBM’s referenced advisory and NVD list affected releases as 8.5, 8.5.1, and 8.6.0.
CVE-2016-5953 describes an information disclosure weakness in IBM Sterling software where a session identifier is transmitted in the URL and may be Base64-encoded in the URL of an error page when a user lacks permission to view a page. NVD lists the issue as CVSS 3.7 (Low) with CWE-200, and the affected CPEs in the record cover IBM Sterling Selling and Fulfillment Foundation versions 9.1.0 through 9.5. IB [truncated]
CVE-2016-5942 is a cross-site scripting issue in IBM Kenexa LMS on Cloud. NVD classifies it as CWE-79 and rates it CVSS 3.0 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Because the flaw allows arbitrary JavaScript to run in the web UI, it can alter trusted-session behavior and may expose credentials or other sensitive session data.