PatchSiren

IBM CVE debriefs · Page 17

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5941

IBM Kenexa LMS is affected by a directory traversal weakness that can allow a remote attacker to request specially crafted URLs containing dot-dot sequences (/../) and read arbitrary files on the system. NVD classifies the issue as CWE-22 and lists affected IBM Kenexa LMS versions from 4.1 through 5.2. The vulnerability is rated Medium (CVSS 5.7) and is focused on confidentiality impact.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5940

CVE-2016-5940 describes a cross-site scripting weakness in IBM Kenexa LMS on Cloud. Because the issue lets a user embed arbitrary JavaScript in the Web UI, it can alter application behavior and expose data within a trusted session. The NVD rates it 5.4 (medium) with low attack complexity, user interaction required, and low impacts to confidentiality and integrity.

LOW IBM CVE published 2017-02-01

CVE-2016-5938

CVE-2016-5938 is a low-severity information disclosure issue in IBM Kenexa LMS on Cloud. According to NVD, the flaw can allow web pages stored locally to be read by another user on the system. The CVE was published on 2017-02-01 and is not listed as a Known Exploited Vulnerability.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5881

CVE-2016-5881 is a cross-site scripting vulnerability in IBM iNotes. According to the NVD record and IBM-linked references, affected users could embed arbitrary JavaScript in the web UI, altering intended behavior and potentially exposing credentials within a trusted session. NVD lists the issue as medium severity (CVSS 6.1) and maps it to CWE-79.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-2992

CVE-2016-2992 is a cross-site scripting vulnerability in IBM InfoSphere BigInsights Web UI. According to the NVD record, the issue can let a user embed arbitrary JavaScript in the interface, which may alter expected UI behavior and expose credentials within a trusted session. IBM references a patch and vendor advisory in the published record.

HIGH IBM CVE published 2017-02-01

CVE-2016-2942

CVE-2016-2942 describes an access-control weakness in IBM UrbanCode Deploy where an authenticated attacker with special permissions could craft a script on the server in a way that causes processes to run on a remote UrbanCode Deploy agent machine. IBM and NVD classify the issue as high severity, with potential impact to confidentiality, integrity, and availability.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-2941

IBM UrbanCode Deploy can create temporary files during step execution that may contain sensitive information, including passwords, which a local user could read. NVD classifies the issue as CWE-200 and assigns a medium-severity CVSS 3.0 score of 5.5, with local access required to exploit it.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-2924

CVE-2016-2924 is a cross-site scripting (XSS) vulnerability in IBM Infosphere BigInsights 4.2. According to NVD, the issue stems from improper validation of user-supplied input and can be triggered through a specially crafted URL. If a victim clicks the link, script may run in the browser in the security context of the hosting website, which can expose cookie-based authentication data.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-0320

CVE-2016-0320 affects IBM UrbanCode Deploy and describes a REST authorization weakness that could allow an authenticated user to modify UCD objects. NVD and the vendor reference indicate the issue can alter the behavior of legitimately triggered processes, making it a meaningful integrity concern for deployment and release automation environments. NVD scores the issue CVSS 3.0 4.3 (Medium).

MEDIUM IBM CVE published 2017-02-01

CVE-2016-0218

CVE-2016-0218 is a cross-site scripting issue in IBM Cognos that can let an attacker run script in a victim’s browser after the victim clicks a specially crafted URL. NVD rates it 5.4/Medium, with network attack, low complexity, required user interaction, and limited confidentiality/integrity impact.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-0217

CVE-2016-0217 is a stored cross-site scripting issue in IBM Cognos Business Intelligence and IBM Cognos Analytics. IBM and NVD describe the flaw as improper validation of user-supplied input, which could let a remote attacker inject script into a page viewed by another user. If successful, the script runs in the context of the hosting web site and could expose cookie-based authentication credentials.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8967

CVE-2016-8967 is a credential exposure issue in IBM BigFix Inventory 9.2. According to the NVD description, user credentials are stored in clear text and can be read by a local user. The NVD CVSS 3.0 vector reflects local access with low privileges and high confidentiality impact.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6117

CVE-2016-6117 describes an information-disclosure issue in IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 where active debugging code can expose sensitive information. The NVD entry classifies the issue as network-reachable, low-complexity, and requiring no privileges or user interaction, but with confidentiality impact only. IBM’s advisory is referenced as the patch source. This is a defensive maintenance [truncated]

HIGH IBM CVE published 2017-02-01

CVE-2016-6105

CVE-2016-6105 is a high-severity access-control flaw in IBM Tivoli Key Lifecycle Manager 2.5 and 2.6. According to NVD, the issue stems from a missing authentication check for a critical resource or function, which allows anonymous users to reach protected areas. The CVE was published on 2017-02-01.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-0371

IBM Tivoli Storage Manager (TSM) can reveal a password in plain text through application trace output when application tracing is enabled. This is a credential-disclosure issue rather than a code-execution flaw, but it can still expose sensitive access credentials to anyone who can read the trace output or related logs.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-9731

CVE-2016-9731 is a cross-site scripting (XSS) vulnerability in IBM Business Process Manager. According to the CVE/NVD record, an attacker with limited privileges and user interaction can embed arbitrary JavaScript in the Web UI, which may alter application behavior and expose credentials within a trusted session. The issue is rated medium severity (CVSS 5.4) and is associated with IBM Business Process Man [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8981

CVE-2016-8981 is a local information disclosure issue in IBM BigFix Inventory / IBM License Metric Tool. According to NVD, the affected software can store web pages locally in a way that allows another user on the same system to read them, creating a confidentiality exposure on shared hosts. NVD rates the issue CVSS v3.0 5.5 (medium) and maps it to CWE-200.

HIGH IBM CVE published 2017-02-01

CVE-2016-8980

CVE-2016-8980 describes an XML External Entity (XXE) weakness in IBM BigFix Inventory v9.2 / 9.2.0. The issue is classified by NVD as CWE-611 and carries a high severity score because it is network reachable, requires only low privileges, and can impact both confidentiality and availability. According to the CVE description, a remote attacker may be able to expose sensitive information or consume availabl [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8966

CVE-2016-8966 is a confidentiality issue in IBM BigFix Inventory v9. NVD describes it as a failure to properly enable HTTP Strict Transport Security (HSTS), which could let a remote attacker use man-in-the-middle techniques to obtain sensitive information. The NVD record maps the issue to IBM BigFix Inventory 9.2 and IBM License Metric Tool 9.2.0, and assigns a medium severity score.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8961

CVE-2016-8961 is an open redirect issue in IBM BigFix Inventory v9 that can be abused for phishing. A remote attacker can lure a user to a crafted link, redirect the browser to a malicious site, and make the destination appear trusted, increasing the chance of credential theft or follow-on attacks.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8943

IBM Tivoli Storage Productivity Center, and related IBM Spectrum Control versions listed by NVD, are vulnerable to cross-site scripting in the Web UI. An authenticated user with limited privileges can embed arbitrary JavaScript, which can alter UI behavior and may expose credentials within a trusted session.

LOW IBM CVE published 2017-02-01

CVE-2016-8942

CVE-2016-8942 is a low-severity authorization weakness affecting IBM Tivoli Storage Productivity Center and related IBM Spectrum Control versions listed by NVD. The issue allows an authenticated user with intimate knowledge of the system to edit a limited set of server properties, creating an integrity risk rather than a confidentiality or availability issue in the supplied CVSS record.

HIGH IBM CVE published 2017-02-01

CVE-2016-8941

CVE-2016-8941 is a cross-site request forgery (CSRF) issue in IBM Tivoli Storage Productivity Center and related Spectrum Control releases. NVD rates it 8.8 High with network access, no privileges required, and user interaction required, reflecting the potential for a trusted user to be induced into performing malicious or unauthorized actions.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8936

CVE-2016-8936 is a cross-site scripting issue in IBM Social Rendering Templates for Digital Data Connector. According to the supplied NVD record, the flaw can let a user embed arbitrary JavaScript in the Web UI, which may alter intended behavior and expose credentials within a trusted session.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8934

CVE-2016-8934 is a cross-site scripting flaw in IBM WebSphere Application Server's Web UI. The vulnerability can let an attacker embed arbitrary JavaScript in a trusted web session, altering UI behavior and potentially exposing credentials.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8922

CVE-2016-8922 is a cross-site scripting (XSS) issue recorded by NVD and mapped to IBM web products, with the record identifying IBM Web Content Manager Production Analytics 4.0 and IBM WebSphere Portal 8.0/8.5 as affected CPEs. The CVSS v3.0 vector shows network reachability but requires user interaction, and the impact is limited to low confidentiality and integrity consequences. The supplied description [truncated]

HIGH IBM CVE published 2017-02-01

CVE-2016-8921

NVD lists CVE-2016-8921 as a high-severity issue affecting IBM FileNet WorkPlace XT 1.1.5. The record describes a remote attacker being able to upload arbitrary files, which can lead to arbitrary code execution on the vulnerable server. NVD rates the issue CVSS 8.8 with a network attack vector, low attack complexity, low privileges required, and high impacts to confidentiality, integrity, and availability.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8920

CVE-2016-8920 is a cross-site scripting issue in IBM Kenexa LMS on Cloud affecting versions 13.1 and 13.2 through 13.2.4. According to the CVE description, affected users can embed arbitrary JavaScript in the web UI, which can alter application behavior and may expose credentials within a trusted session. NVD assigns CVSS 3.0 5.4 (Medium) with network access, low attack complexity, low privileges, require [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8918

CVE-2016-8918 is a medium-severity IBM Integration Bus issue where, under non-default configurations, a remote user could authenticate without providing valid credentials. The NVD record cites IBM’s vendor advisory (ref-4) and assigns a CVSS 3.0 vector of AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N, indicating a network-reachable authentication weakness with integrity impact. Defenders should treat this as an acc [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8913

CVE-2016-8913 is a directory traversal vulnerability in IBM Kenexa LMS on Cloud. According to the CVE description, a remote attacker could send specially crafted URL requests containing dot-dot sequences (/../) to view arbitrary files on the system. NVD classifies the weakness as CWE-22 and rates it Medium with CVSS 3.0 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating network reachability, low attac [truncated]