PatchSiren

IBM CVE debriefs · Page 19

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-6000

CVE-2016-6000 is a cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform. According to the NVD record, affected users could embed arbitrary JavaScript in the Web UI, which can alter intended application behavior and may expose credentials or other sensitive data within a trusted session. NVD rates the issue CVSS 3.0 6.1 (Medium).

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5994

CVE-2016-5994 is an information disclosure flaw in IBM InfoSphere Information Server. According to the NVD record, an authenticated user could browse any file on the engine tier and examine its contents. The issue was published on 2017-02-01 and is rated CVSS 6.5 MEDIUM, reflecting meaningful confidentiality impact with required authentication.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5990

CVE-2016-5990 describes an access-control weakness in IBM Security Privileged Identity Manager Virtual Appliance where an authenticated user could upload malicious files that would then be automatically executed by the server. The NVD record maps the issue to IBM Security Privileged Identity Manager Virtual Appliance versions 2.0.2 and 2.1 and rates it as medium severity. Because the vulnerable action req [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5988

CVE-2016-5988 is an information disclosure issue in IBM Security Privileged Identity Manager Virtual Appliance. According to the NVD record, generated error messages could reveal sensitive information to an authenticated user. The issue is rated MEDIUM, with a CVSS 3.0 vector of AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating remote reachability, low attack complexity, and high confidentiality impact. NVD [truncated]

HIGH IBM CVE published 2017-02-01

CVE-2016-5985

CVE-2016-5985 is a high-severity buffer overflow in the IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client when Journal-Based Backup is enabled. According to the CVE record, a local attacker could overflow a buffer and potentially execute arbitrary code or crash the system.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5984

CVE-2016-5984 affects IBM InfoSphere Information Server and is described as a cross-frame scripting issue caused by insufficient HTML iframe protection. According to the published record, a remote attacker could use a specially crafted URL to send a user to an attacker-controlled page, creating conditions for clickjacking or other client-side browser attacks. NVD assigns the issue CVSS 3.0 6.1 (Medium) an [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5980

CVE-2016-5980 is a cross-site scripting vulnerability in IBM TRIRIGA Application Platform. According to the CVE description, it allows users to embed arbitrary JavaScript in the Web UI, which can alter intended functionality and potentially disclose credentials within a trusted session. NVD rates it as medium severity (CVSS 5.4) and records it as a network-reachable issue that requires low privileges and [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5966

CVE-2016-5966 describes a missing HTTP Strict Transport Security (HSTS) control in IBM Security Privileged Identity Manager Virtual Appliance. According to the NVD record, this weakness can expose sensitive information to a remote attacker using man-in-the-middle techniques. NVD rates the issue as CVSS 3.0 5.9 (Medium), with network attack vector and no privileges or user interaction required.

CRITICAL IBM CVE published 2017-02-01

CVE-2016-5964

CVE-2016-5964 describes a weak account lockout control in IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2. Because the lockout setting was inadequate, a remote attacker could repeatedly guess credentials and increase the chance of successful account compromise. NVD rates the issue Critical with a 9.8 CVSS v3.0 score, reflecting network accessibility and the potential for full conf [truncated]

HIGH IBM CVE published 2017-02-01

CVE-2016-5958

CVE-2016-5958 is a high-severity information disclosure vulnerability in IBM Security Privileged Identity Manager. In SSL mode, the product could fail to mark the session cookie as Secure, which could allow a remote attacker to intercept the cookie during HTTP session traffic and obtain sensitive information. NVD lists affected versions as IBM Security Privileged Identity Manager 2.0.2 and 2.1, with a CVS [truncated]

HIGH IBM CVE published 2017-02-01

CVE-2016-5952

CVE-2016-5952 is a high-severity SQL injection vulnerability in IBM Kenexa LCMS Premier on Cloud. According to the public record, a remote attacker could send specially crafted SQL statements and potentially view, add, modify, or delete data in the back-end database.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5951

CVE-2016-5951 is a cross-site scripting issue in IBM Kenexa LCMS Premier on Cloud. According to the NVD record, user-controlled script can be embedded in the Web UI, which may alter application behavior and expose credentials within a trusted session. NVD rates the issue as medium severity and maps it to CWE-79.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5950

CVE-2016-5950 describes a credential exposure issue in IBM Kenexa LCMS Premier on Cloud. According to the NVD record and IBM advisory reference, user credentials were stored in clear text and could be read by an authenticated user. Because the flaw requires authentication but exposes highly sensitive credentials, it is a meaningful confidentiality risk for any organization running affected versions.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5949

CVE-2016-5949 describes a sensitive-data exposure issue in IBM Kenexa LCMS Premier on Cloud. According to NVD, an authenticated user could obtain sensitive user data by sending a specially crafted HTTP request. The issue affects IBM Kenexa LCMS Premier versions 9.1 through 10.1 and is scored CVSS 4.3 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N), indicating a network-reachable confidentiality impact without integ [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5948

CVE-2016-5948 is a cross-site scripting issue in IBM Kenexa LCMS Premier on Cloud. According to NVD, the flaw can let a user embed arbitrary JavaScript in the web UI, which can alter intended application behavior and may lead to credential disclosure within a trusted session. NVD rates the issue CVSS 3.0 5.4 (Medium).

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5939

CVE-2016-5939 is a SQL injection vulnerability in IBM Kenexa LMS on Cloud. NVD lists affected versions from 4.1 through 5.2, and the issue can let a remote attacker manipulate backend database data.

HIGH IBM CVE published 2017-02-01

CVE-2016-5937

CVE-2016-5937 describes a cross-site request forgery issue in IBM Kenexa LCMS Premier on Cloud. NVD lists affected versions from 9.0 through 10.2 and rates the issue CVSS 3.0 8.8 (High). Because the attack requires a user interaction while the application trusts the resulting request, state-changing functionality may be abused if CSRF protections are missing or ineffective.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5899

CVE-2016-5899 is a cross-site scripting issue in IBM Jazz Reporting Service (JRS). According to the NVD record, affected versions include JRS 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, and 6.0.2. The issue allows a user to embed arbitrary JavaScript in the Web UI, which can alter intended functionality and may expose credentials within a trusted session.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5898

CVE-2016-5898 is a medium-severity information disclosure issue in IBM Jazz Reporting Service (JRS). According to the NVD record, an attacker could send a direct request and obtain sensitive information because JSON serialization was not properly restricted. The affected NVD CPEs include JRS 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, and 6.0.2.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5897

CVE-2016-5897 is an HTML injection vulnerability in IBM Jazz Reporting Service (JRS). A remote attacker could inject malicious HTML that, when viewed by a victim, executes in the browser within the security context of the hosting site. IBM’s advisory-linked NVD entry identifies affected JRS versions 6.0, 6.0.1, and 6.0.2 and classifies the issue as CWE-79 with a medium CVSS score of 5.4.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5896

CVE-2016-5896 is an information disclosure issue in IBM Maximo Asset Management and related Maximo industry solutions. According to the CVE record, a failed login attempt in the Cognos browser could trigger a stack trace that reveals sensitive information. NVD rates the issue as medium severity (CVSS 5.3) with network attack vector and no privileges or user interaction required.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5884

CVE-2016-5884 is a cross-site scripting issue in IBM iNotes that can let an attacker embed arbitrary JavaScript in the Web UI. Because the code runs in a trusted session, the impact can include credentials disclosure and other unauthorized actions in the context of the affected user. NVD publishes this CVE as modified on 2017-02-01 and updated again on 2026-05-13.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5882

CVE-2016-5882 is a cross-site scripting issue in IBM iNotes, with NVD also listing affected IBM Domino and iNotes versions. The vulnerability can let an attacker embed arbitrary JavaScript in the Web UI, which may alter application behavior and expose credentials within a trusted session. NVD rates the issue 6.1 (MEDIUM) and maps it to CWE-79.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5880

CVE-2016-5880 is a cross-site scripting vulnerability in IBM iNotes that can let a user embed arbitrary JavaScript in the web UI. The impact described in the record is alteration of intended functionality and possible credential disclosure within a trusted session. NVD rates the issue as medium severity (CVSS 5.4) and ties it to CWE-79.

HIGH IBM CVE published 2017-02-01

CVE-2016-3053

CVE-2016-3053 is an IBM AIX vulnerability described by NVD as allowing a locally authenticated user to obtain root-level privileges. The issue is rated High severity with a CVSS 3.0 score of 7.8, reflecting a local attack vector and full impacts to confidentiality, integrity, and availability. The supplied corpus does not provide the underlying flaw type, so the safest interpretation is a privilege-escala [truncated]

LOW IBM CVE published 2017-02-01

CVE-2016-3046

CVE-2016-3046 is a SQL injection vulnerability in IBM Security Access Manager products. NVD links the issue to IBM Security Access Manager for Web 8.0 firmware, IBM Security Access Manager for Mobile, and IBM Security Access Manager 9.0 firmware. The NVD CVSS v3.0 vector shows network access, low complexity, high privileges required, no user interaction, and limited confidentiality impact.

LOW IBM CVE published 2017-02-01

CVE-2016-3045

CVE-2016-3045 describes an information-disclosure issue in IBM Security Access Manager for Web and related IBM Access Manager products where sensitive data is placed in URL parameters. If those URLs are later exposed through server logs, browser history, or the HTTP Referer header, unauthorized parties may see the information. NVD rates the issue low severity and classifies it as CWE-200.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3043

CVE-2016-3043 is an IBM information-disclosure issue tied to HTTP Strict Transport Security not being properly enabled. In affected IBM Security Access Manager deployments, a remote attacker positioned in the network path could use man-in-the-middle techniques to try to obtain sensitive information. The issue was published by the CVE program on 2017-02-01 and is rated medium severity in the supplied record.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3035

IBM AppScan Source contains an information disclosure issue where browsing testlinks on the server could reveal sensitive information. NVD rates the issue CVSS 5.3 (medium), and the affected versions listed are 9.0.1, 9.0.2, and 9.0.3.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3034

CVE-2016-3034 affects IBM AppScan Source and is rated medium severity (CVSS 4.4). The issue is described as a one-way hash used without salt to protect highly sensitive information, which can make that data easier to recover if an attacker already has local access. NVD assigns CVE-2016-3034 to IBM Security AppScan Source 9.0.1, 9.0.2, and 9.0.3, with confidentiality impact only and no integrity or availab [truncated]