PatchSiren

IBM CVE debriefs · Page 18

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8912

CVE-2016-8912 is an information-disclosure issue in IBM Kenexa LMS on Cloud. According to the NVD record, affected versions include IBM Kenexa LMS on Cloud 13.1 and 13.2 through 13.2.4, where potentially sensitive information can be stored in log files and read by an authenticated user. The issue is rated CVSS 4.3 (Medium) and maps to CWE-532 (Insertion of Sensitive Information into Log File).

MEDIUM IBM CVE published 2017-02-01

CVE-2016-8911

CVE-2016-8911 affects IBM Kenexa LMS on Cloud 13.1 and 13.2 through 13.2.4. A remote attacker can persuade a victim to visit a malicious website and hijack the victim's click actions, which could be used to enable further attacks. NVD rates the issue medium severity and records that user interaction is required.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6126

CVE-2016-6126 is a path traversal vulnerability in IBM Kenexa LMS on Cloud. A remote attacker could use specially crafted URL requests containing dot-dot sequences (/../) to access files outside the intended directory scope and view arbitrary files on the system. The affected versions listed by NVD are IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, and 13.2.4.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6125

CVE-2016-6125 is a cross-site scripting issue in IBM Kenexa LMS on Cloud affecting versions 13.1 and 13.2 through 13.2.4. NVD describes the issue as allowing users to embed arbitrary JavaScript in the Web UI, which can alter application behavior and may expose credentials within a trusted session. The CVSS v3.0 score is 5.4 (Medium).

HIGH IBM CVE published 2017-02-01

CVE-2016-6124

CVE-2016-6124 is a high-severity IBM Kenexa LMS on Cloud vulnerability involving arbitrary file upload. According to the NVD record, a remote attacker with low privileges could upload arbitrary files and potentially execute code on the vulnerable server. Affected versions listed by NVD include 13.1, 13.2, 13.2.2, 13.2.3, and 13.2.4.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6123

CVE-2016-6123 is a cross-site scripting issue in IBM Kenexa LMS on Cloud. According to the CVE description, affected users can embed arbitrary JavaScript in the Web UI, which can alter intended application behavior and may lead to credential disclosure within a trusted session. NVD assigns a medium severity score of 5.4 with a CVSS v3.0 vector of AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6122

CVE-2016-6122 is an information disclosure issue in IBM Kenexa LMS on Cloud. In affected versions, an authenticated user can receive answers to security questions in a response, exposing sensitive account recovery data. The CVE was published on 2017-02-01 and is rated Medium severity with a CVSS 3.0 score of 4.3.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6113

CVE-2016-6113 is a cross-site scripting issue affecting IBM's web UI ecosystem. According to the CVE description, users can embed arbitrary JavaScript in the Web UI, which can alter intended functionality and potentially expose credentials within a trusted session. NVD rates the issue as medium severity and maps it to CWE-79.

CRITICAL IBM CVE published 2017-02-01

CVE-2016-6090

CVE-2016-6090 is a critical IBM WebSphere Commerce vulnerability with network reachability and no authentication or user interaction required, according to the NVD CVSS v3.1 vector. NVD describes the issue as unspecified, but its impact is severe: disclosure of user personal data, unauthorized administrative operations, and possible denial of service. Organizations running affected WebSphere Commerce rele [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6085

CVE-2016-6085 is a medium-severity IBM BigFix Platform issue that NVD describes as allowing a local-network attacker to crash BES and relay servers. NVD assigns CVSS 6.5 (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and maps the weakness to CWE-284. The vulnerable CPEs listed by NVD are IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6084

CVE-2016-6084 is a denial-of-service vulnerability in IBM BigFix Platform. According to the NVD record, a specially crafted XMLSchema request sent from an adjacent network could crash the BES server, affecting availability without indicating confidentiality or integrity impact.

CRITICAL IBM CVE published 2017-02-01

CVE-2016-6082

CVE-2016-6082 is a critical vulnerability in IBM BigFix Platform that NVD describes as a use-after-free race condition that can allow remote code execution. The NVD record lists affected IBM BigFix Platform versions 9.0, 9.1, 9.2, and 9.5, and maps the issue to CWE-416. Because the CVSS v3.0 vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, this should be treated as an urgent patching and validation item for [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6080

CVE-2016-6080 is an information disclosure issue affecting the WebAdmin context in IBM WebSphere Message Broker 8.0. The vulnerable component can allow directory listings, which may reveal sensitive information to an attacker. The issue is rated medium severity (CVSS 5.3) and is documented by NVD with IBM PSIRT references to a vendor advisory and patch guidance.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6072

CVE-2016-6072 is a cross-site scripting (XSS) issue in IBM Maximo Asset Management and related IBM Maximo/Tivoli products. IBM’s advisory and NVD describe a flaw that can let an authenticated user embed arbitrary JavaScript in the Web UI, altering application behavior and potentially exposing credentials or other data within a trusted session. The public record shows this was disclosed on 2017-02-01 and l [truncated]

HIGH IBM CVE published 2017-02-01

CVE-2016-6065

CVE-2016-6065 affects IBM Security Guardium Database Activity Monitor appliances and describes a local command-injection issue that could let a local user execute commands as root. NVD lists the issue as High severity with a CVSS 3.0 score of 7.8, and IBM references vendor patch guidance in its advisory.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6061

CVE-2016-6061 is a cross-site scripting (XSS) vulnerability in an IBM web UI context. Per the vendor/NVD description, the issue can let a user embed arbitrary JavaScript in the interface, which can alter intended functionality and may expose credentials within a trusted session. NVD rates the issue as medium severity and maps it to IBM Rational Collaborative Lifecycle Management versions 4.0.0 through 6.0.2.

HIGH IBM CVE published 2017-02-01

CVE-2016-6059

CVE-2016-6059 is an IBM InfoSphere XML processing weakness that can be abused through XML External Entity (XXE) handling. According to NVD, the issue can lead to sensitive information exposure and denial of service through memory consumption. IBM’s advisory and the NVD record identify affected InfoSphere DataStage and InfoSphere Information Server versions, with a CVSS 3.0 score of 8.1 (High).

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6054

CVE-2016-6054 is a medium-severity cross-site scripting issue affecting IBM Jazz-related Web UI components. According to the CVE description, an attacker can embed arbitrary JavaScript in the interface, which can alter functionality and potentially expose credentials within a trusted session. NVD rates the issue CVSS 3.0 5.4 and lists affected IBM Jazz Reporting Service versions 5.0 through 6.0.2.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6047

CVE-2016-6047 is a cross-site scripting vulnerability in IBM Jazz Reporting Service (JRS). According to NVD and IBM-linked references, a user can embed arbitrary JavaScript in the web UI, which can alter application behavior and may expose credentials within a trusted session. The issue is rated medium severity and is associated with IBM JRS 6.0.2 in the NVD record.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6046

CVE-2016-6046 describes a cross-site scripting flaw in IBM Tivoli Storage Manager Operations Center. The issue allows a user to embed arbitrary JavaScript in the web UI, which can alter intended application behavior and may expose credentials within a trusted session. NVD rates the issue as medium severity (CVSS 5.4).

HIGH IBM CVE published 2017-02-01

CVE-2016-6045

IBM Tivoli Storage Manager Operations Center contains a cross-site request forgery (CSRF) vulnerability that can let an attacker trigger unauthorized actions through a trusted user’s browser/session.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6044

CVE-2016-6044 is a medium-severity access-control issue in IBM Tivoli Storage Manager Operations Center. According to the NVD record, an authenticated attacker could enable or disable the application's REST API, which may let them bypass intended operational policy boundaries. The issue was publicly disclosed in the NVD record on 2017-02-01, with IBM PSIRT advisory references included in the record.

HIGH IBM CVE published 2017-02-01

CVE-2016-6043

CVE-2016-6043 affects IBM Tivoli Storage Manager Operations Center and can let a local user take over a previously logged-in user’s session when expiration is not enforced. IBM’s advisory is cited by NVD, and the issue is rated High with confidentiality, integrity, and availability impact.

HIGH IBM CVE published 2017-02-01

CVE-2016-6042

CVE-2016-6042 is a high-severity IBM AppScan Enterprise Edition vulnerability that can lead to arbitrary code execution in the context of the victim user. The issue is tied to improper handling of objects in memory (CWE-119) and is triggered when a victim opens specially crafted content. NVD rates the issue CVSS 3.0 7.3 (High) with local access, low privileges, and user interaction required.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6040

CVE-2016-6040 is an IBM session management flaw that can allow an authenticated user to take over a previously logged-in session when expiration is not enforced. NVD assigns CWE-384 (Session Fixation) and rates the issue Medium severity with limited confidentiality, integrity, and availability impact. The vulnerability was published on 2017-02-01, and the provided NVD data lists multiple affected IBM Rati [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6039

CVE-2016-6039 is a cross-site scripting (XSS) vulnerability in IBM Jazz Reporting Service (JRS). According to the NVD record, affected releases include JRS 6.0, 6.0.1, and 6.0.2. The issue can let a user embed arbitrary JavaScript in the web UI, which may alter intended application behavior and could expose credentials within a trusted session.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6034

CVE-2016-6034 is a credential-disclosure issue in IBM Tivoli Storage Manager for Virtual Environments (Data Protection for VMware). According to the NVD record, a user with high privileges could be exposed to Windows domain credentials. IBM’s advisory is listed as the vendor reference for patch guidance.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6030

CVE-2016-6030 is a medium-severity cross-site scripting issue published on 2017-02-01. According to the supplied NVD record, the weakness affects IBM Jazz Foundation-related web UI components and IBM Rational Collaborative Lifecycle Management versions 4.0.0 through 6.0.2. The risk is most relevant where authenticated users can be induced to render attacker-controlled content in a trusted session.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6028

CVE-2016-6028 is a low-complexity information disclosure issue in IBM Jazz technology-based products. IBM’s advisory and NVD describe a case where an attacker could view work item titles they were not privileged to see. The impact is limited to confidentiality, but it can still expose sensitive project metadata.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6020

CVE-2016-6020 describes an open redirect weakness in IBM Sterling B2B Integrator Standard Edition that could be used in phishing-style attacks. A remote attacker could lure a victim to a specially crafted website and cause the victim’s browser to be redirected to a malicious site while displaying a trusted-looking URL path, increasing the chance of credential theft or other follow-on abuse. NVD assigns a [truncated]