These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2016-8912 is an information-disclosure issue in IBM Kenexa LMS on Cloud. According to the NVD record, affected versions include IBM Kenexa LMS on Cloud 13.1 and 13.2 through 13.2.4, where potentially sensitive information can be stored in log files and read by an authenticated user. The issue is rated CVSS 4.3 (Medium) and maps to CWE-532 (Insertion of Sensitive Information into Log File).
CVE-2016-8911 affects IBM Kenexa LMS on Cloud 13.1 and 13.2 through 13.2.4. A remote attacker can persuade a victim to visit a malicious website and hijack the victim's click actions, which could be used to enable further attacks. NVD rates the issue medium severity and records that user interaction is required.
CVE-2016-6126 is a path traversal vulnerability in IBM Kenexa LMS on Cloud. A remote attacker could use specially crafted URL requests containing dot-dot sequences (/../) to access files outside the intended directory scope and view arbitrary files on the system. The affected versions listed by NVD are IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, and 13.2.4.
CVE-2016-6125 is a cross-site scripting issue in IBM Kenexa LMS on Cloud affecting versions 13.1 and 13.2 through 13.2.4. NVD describes the issue as allowing users to embed arbitrary JavaScript in the Web UI, which can alter application behavior and may expose credentials within a trusted session. The CVSS v3.0 score is 5.4 (Medium).
CVE-2016-6124 is a high-severity IBM Kenexa LMS on Cloud vulnerability involving arbitrary file upload. According to the NVD record, a remote attacker with low privileges could upload arbitrary files and potentially execute code on the vulnerable server. Affected versions listed by NVD include 13.1, 13.2, 13.2.2, 13.2.3, and 13.2.4.
CVE-2016-6123 is a cross-site scripting issue in IBM Kenexa LMS on Cloud. According to the CVE description, affected users can embed arbitrary JavaScript in the Web UI, which can alter intended application behavior and may lead to credential disclosure within a trusted session. NVD assigns a medium severity score of 5.4 with a CVSS v3.0 vector of AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N.
CVE-2016-6122 is an information disclosure issue in IBM Kenexa LMS on Cloud. In affected versions, an authenticated user can receive answers to security questions in a response, exposing sensitive account recovery data. The CVE was published on 2017-02-01 and is rated Medium severity with a CVSS 3.0 score of 4.3.
CVE-2016-6113 is a cross-site scripting issue affecting IBM's web UI ecosystem. According to the CVE description, users can embed arbitrary JavaScript in the Web UI, which can alter intended functionality and potentially expose credentials within a trusted session. NVD rates the issue as medium severity and maps it to CWE-79.
CVE-2016-6090 is a critical IBM WebSphere Commerce vulnerability with network reachability and no authentication or user interaction required, according to the NVD CVSS v3.1 vector. NVD describes the issue as unspecified, but its impact is severe: disclosure of user personal data, unauthorized administrative operations, and possible denial of service. Organizations running affected WebSphere Commerce rele [truncated]
CVE-2016-6085 is a medium-severity IBM BigFix Platform issue that NVD describes as allowing a local-network attacker to crash BES and relay servers. NVD assigns CVSS 6.5 (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and maps the weakness to CWE-284. The vulnerable CPEs listed by NVD are IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5.
CVE-2016-6084 is a denial-of-service vulnerability in IBM BigFix Platform. According to the NVD record, a specially crafted XMLSchema request sent from an adjacent network could crash the BES server, affecting availability without indicating confidentiality or integrity impact.
CVE-2016-6082 is a critical vulnerability in IBM BigFix Platform that NVD describes as a use-after-free race condition that can allow remote code execution. The NVD record lists affected IBM BigFix Platform versions 9.0, 9.1, 9.2, and 9.5, and maps the issue to CWE-416. Because the CVSS v3.0 vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, this should be treated as an urgent patching and validation item for [truncated]
CVE-2016-6080 is an information disclosure issue affecting the WebAdmin context in IBM WebSphere Message Broker 8.0. The vulnerable component can allow directory listings, which may reveal sensitive information to an attacker. The issue is rated medium severity (CVSS 5.3) and is documented by NVD with IBM PSIRT references to a vendor advisory and patch guidance.
CVE-2016-6072 is a cross-site scripting (XSS) issue in IBM Maximo Asset Management and related IBM Maximo/Tivoli products. IBM’s advisory and NVD describe a flaw that can let an authenticated user embed arbitrary JavaScript in the Web UI, altering application behavior and potentially exposing credentials or other data within a trusted session. The public record shows this was disclosed on 2017-02-01 and l [truncated]
CVE-2016-6065 affects IBM Security Guardium Database Activity Monitor appliances and describes a local command-injection issue that could let a local user execute commands as root. NVD lists the issue as High severity with a CVSS 3.0 score of 7.8, and IBM references vendor patch guidance in its advisory.
CVE-2016-6061 is a cross-site scripting (XSS) vulnerability in an IBM web UI context. Per the vendor/NVD description, the issue can let a user embed arbitrary JavaScript in the interface, which can alter intended functionality and may expose credentials within a trusted session. NVD rates the issue as medium severity and maps it to IBM Rational Collaborative Lifecycle Management versions 4.0.0 through 6.0.2.
CVE-2016-6059 is an IBM InfoSphere XML processing weakness that can be abused through XML External Entity (XXE) handling. According to NVD, the issue can lead to sensitive information exposure and denial of service through memory consumption. IBM’s advisory and the NVD record identify affected InfoSphere DataStage and InfoSphere Information Server versions, with a CVSS 3.0 score of 8.1 (High).
CVE-2016-6054 is a medium-severity cross-site scripting issue affecting IBM Jazz-related Web UI components. According to the CVE description, an attacker can embed arbitrary JavaScript in the interface, which can alter functionality and potentially expose credentials within a trusted session. NVD rates the issue CVSS 3.0 5.4 and lists affected IBM Jazz Reporting Service versions 5.0 through 6.0.2.
CVE-2016-6047 is a cross-site scripting vulnerability in IBM Jazz Reporting Service (JRS). According to NVD and IBM-linked references, a user can embed arbitrary JavaScript in the web UI, which can alter application behavior and may expose credentials within a trusted session. The issue is rated medium severity and is associated with IBM JRS 6.0.2 in the NVD record.
CVE-2016-6046 describes a cross-site scripting flaw in IBM Tivoli Storage Manager Operations Center. The issue allows a user to embed arbitrary JavaScript in the web UI, which can alter intended application behavior and may expose credentials within a trusted session. NVD rates the issue as medium severity (CVSS 5.4).
IBM Tivoli Storage Manager Operations Center contains a cross-site request forgery (CSRF) vulnerability that can let an attacker trigger unauthorized actions through a trusted user’s browser/session.
CVE-2016-6044 is a medium-severity access-control issue in IBM Tivoli Storage Manager Operations Center. According to the NVD record, an authenticated attacker could enable or disable the application's REST API, which may let them bypass intended operational policy boundaries. The issue was publicly disclosed in the NVD record on 2017-02-01, with IBM PSIRT advisory references included in the record.
CVE-2016-6043 affects IBM Tivoli Storage Manager Operations Center and can let a local user take over a previously logged-in user’s session when expiration is not enforced. IBM’s advisory is cited by NVD, and the issue is rated High with confidentiality, integrity, and availability impact.
CVE-2016-6042 is a high-severity IBM AppScan Enterprise Edition vulnerability that can lead to arbitrary code execution in the context of the victim user. The issue is tied to improper handling of objects in memory (CWE-119) and is triggered when a victim opens specially crafted content. NVD rates the issue CVSS 3.0 7.3 (High) with local access, low privileges, and user interaction required.
CVE-2016-6040 is an IBM session management flaw that can allow an authenticated user to take over a previously logged-in session when expiration is not enforced. NVD assigns CWE-384 (Session Fixation) and rates the issue Medium severity with limited confidentiality, integrity, and availability impact. The vulnerability was published on 2017-02-01, and the provided NVD data lists multiple affected IBM Rati [truncated]
CVE-2016-6039 is a cross-site scripting (XSS) vulnerability in IBM Jazz Reporting Service (JRS). According to the NVD record, affected releases include JRS 6.0, 6.0.1, and 6.0.2. The issue can let a user embed arbitrary JavaScript in the web UI, which may alter intended application behavior and could expose credentials within a trusted session.
CVE-2016-6034 is a credential-disclosure issue in IBM Tivoli Storage Manager for Virtual Environments (Data Protection for VMware). According to the NVD record, a user with high privileges could be exposed to Windows domain credentials. IBM’s advisory is listed as the vendor reference for patch guidance.
CVE-2016-6030 is a medium-severity cross-site scripting issue published on 2017-02-01. According to the supplied NVD record, the weakness affects IBM Jazz Foundation-related web UI components and IBM Rational Collaborative Lifecycle Management versions 4.0.0 through 6.0.2. The risk is most relevant where authenticated users can be induced to render attacker-controlled content in a trusted session.
CVE-2016-6028 is a low-complexity information disclosure issue in IBM Jazz technology-based products. IBM’s advisory and NVD describe a case where an attacker could view work item titles they were not privileged to see. The impact is limited to confidentiality, but it can still expose sensitive project metadata.
CVE-2016-6020 describes an open redirect weakness in IBM Sterling B2B Integrator Standard Edition that could be used in phishing-style attacks. A remote attacker could lure a victim to a specially crafted website and cause the victim’s browser to be redirected to a malicious site while displaying a trusted-looking URL path, increasing the chance of credential theft or other follow-on abuse. NVD assigns a [truncated]