PatchSiren

IBM CVE debriefs · Page 20

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5899

CVE-2016-5899 is a cross-site scripting issue in IBM Jazz Reporting Service (JRS). According to the NVD record, affected versions include JRS 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, and 6.0.2. The issue allows a user to embed arbitrary JavaScript in the Web UI, which can alter intended functionality and may expose credentials within a trusted session.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5898

CVE-2016-5898 is a medium-severity information disclosure issue in IBM Jazz Reporting Service (JRS). According to the NVD record, an attacker could send a direct request and obtain sensitive information because JSON serialization was not properly restricted. The affected NVD CPEs include JRS 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, and 6.0.2.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5897

CVE-2016-5897 is an HTML injection vulnerability in IBM Jazz Reporting Service (JRS). A remote attacker could inject malicious HTML that, when viewed by a victim, executes in the browser within the security context of the hosting site. IBM’s advisory-linked NVD entry identifies affected JRS versions 6.0, 6.0.1, and 6.0.2 and classifies the issue as CWE-79 with a medium CVSS score of 5.4.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5896

CVE-2016-5896 is an information disclosure issue in IBM Maximo Asset Management and related Maximo industry solutions. According to the CVE record, a failed login attempt in the Cognos browser could trigger a stack trace that reveals sensitive information. NVD rates the issue as medium severity (CVSS 5.3) with network attack vector and no privileges or user interaction required.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5884

CVE-2016-5884 is a cross-site scripting issue in IBM iNotes that can let an attacker embed arbitrary JavaScript in the Web UI. Because the code runs in a trusted session, the impact can include credentials disclosure and other unauthorized actions in the context of the affected user. NVD publishes this CVE as modified on 2017-02-01 and updated again on 2026-05-13.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5882

CVE-2016-5882 is a cross-site scripting issue in IBM iNotes, with NVD also listing affected IBM Domino and iNotes versions. The vulnerability can let an attacker embed arbitrary JavaScript in the Web UI, which may alter application behavior and expose credentials within a trusted session. NVD rates the issue 6.1 (MEDIUM) and maps it to CWE-79.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-5880

CVE-2016-5880 is a cross-site scripting vulnerability in IBM iNotes that can let a user embed arbitrary JavaScript in the web UI. The impact described in the record is alteration of intended functionality and possible credential disclosure within a trusted session. NVD rates the issue as medium severity (CVSS 5.4) and ties it to CWE-79.

HIGH IBM CVE published 2017-02-01

CVE-2016-3053

CVE-2016-3053 is an IBM AIX vulnerability described by NVD as allowing a locally authenticated user to obtain root-level privileges. The issue is rated High severity with a CVSS 3.0 score of 7.8, reflecting a local attack vector and full impacts to confidentiality, integrity, and availability. The supplied corpus does not provide the underlying flaw type, so the safest interpretation is a privilege-escala [truncated]

LOW IBM CVE published 2017-02-01

CVE-2016-3046

CVE-2016-3046 is a SQL injection vulnerability in IBM Security Access Manager products. NVD links the issue to IBM Security Access Manager for Web 8.0 firmware, IBM Security Access Manager for Mobile, and IBM Security Access Manager 9.0 firmware. The NVD CVSS v3.0 vector shows network access, low complexity, high privileges required, no user interaction, and limited confidentiality impact.

LOW IBM CVE published 2017-02-01

CVE-2016-3045

CVE-2016-3045 describes an information-disclosure issue in IBM Security Access Manager for Web and related IBM Access Manager products where sensitive data is placed in URL parameters. If those URLs are later exposed through server logs, browser history, or the HTTP Referer header, unauthorized parties may see the information. NVD rates the issue low severity and classifies it as CWE-200.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3043

CVE-2016-3043 is an IBM information-disclosure issue tied to HTTP Strict Transport Security not being properly enabled. In affected IBM Security Access Manager deployments, a remote attacker positioned in the network path could use man-in-the-middle techniques to try to obtain sensitive information. The issue was published by the CVE program on 2017-02-01 and is rated medium severity in the supplied record.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3035

IBM AppScan Source contains an information disclosure issue where browsing testlinks on the server could reveal sensitive information. NVD rates the issue CVSS 5.3 (medium), and the affected versions listed are 9.0.1, 9.0.2, and 9.0.3.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3034

CVE-2016-3034 affects IBM AppScan Source and is rated medium severity (CVSS 4.4). The issue is described as a one-way hash used without salt to protect highly sensitive information, which can make that data easier to recover if an attacker already has local access. NVD assigns CVE-2016-3034 to IBM Security AppScan Source 9.0.1, 9.0.2, and 9.0.3, with confidentiality impact only and no integrity or availab [truncated]

HIGH IBM CVE published 2017-02-01

CVE-2016-3029

CVE-2016-3029 is a cross-site request forgery (CSRF) issue in IBM Security Access Manager for Web and related IBM Security Access Manager builds listed by NVD. If a trusted user is induced to interact with attacker-controlled content, malicious requests can be sent through the user’s authenticated session and perform unauthorized actions in the application. NVD rates the issue CVSS 8.8 with network access [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3027

CVE-2016-3027 describes an XML External Entity (XXE) issue in IBM Security Access Manager that can lead to denial of service and, in some cases, exposure of sensitive information. NVD rates it Medium severity (CVSS 6.5) and links the issue to IBM Security Access Manager for Web and Mobile firmware versions. IBM PSIRT is cited as the patch/vendor advisory source.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3024

CVE-2016-3024 is an information disclosure issue in IBM Security Access Manager for Web and related Mobile/Web firmware. According to NVD, web pages can be stored locally in a way that may allow another user on the same system to read them. The weakness is classified as CWE-200 and scored CVSS 3.0 4.0 (AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), so the primary concern is unintended exposure of locally stored co [truncated]

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3023

CVE-2016-3023 is an information-disclosure issue in IBM Security Access Manager for Web and related IBM firmware entries listed by NVD. An unauthenticated remote user can trigger the condition by entering invalid file names, which may reveal sensitive information. NVD rates the issue Medium and maps it to CWE-200.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3022

CVE-2016-3022 describes an information disclosure issue in IBM Security Access Manager products where incorrect file permissions could let an authenticated user access highly sensitive information. The published CVSS vector rates this as a network-reachable issue that requires low privileges and no user interaction, with high confidentiality impact and no stated integrity or availability impact. The NVD r [truncated]

LOW IBM CVE published 2017-02-01

CVE-2016-3021

CVE-2016-3021 is a low-severity information-disclosure issue in IBM Security Access Manager. According to the CVE description, an authenticated attacker could trigger an error message with a specially crafted HTTP request and learn sensitive information from that response. NVD classifies the weakness as CWE-200 and assigns a low confidentiality impact with no integrity or availability impact.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3018

CVE-2016-3018 is a cross-site scripting (XSS) issue in IBM Security Access Manager that can let an attacker embed arbitrary JavaScript in the Web UI. According to the CVE description, that can alter intended UI behavior and may expose credentials within a trusted session. NVD classifies the weakness as CWE-79 and rates it CVSS 3.0 6.1 (Medium).

HIGH IBM CVE published 2017-02-01

CVE-2016-3017

CVE-2016-3017 describes an IBM Security Access Manager for Web issue that could let a remote attacker obtain sensitive information because of security misconfigurations. NVD rates the issue as network-exploitable with no authentication or user interaction required, and the impact is confidentiality only but high.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-3016

CVE-2016-3016 is a medium-severity IBM Security Access Manager issue in which patch, image backup, and other update handling did not sufficiently verify the origin and integrity of code. According to the NVD description, an authenticated attacker could use this weakness to load malicious code. The issue was publicly disclosed on 2017-02-01 and is tracked by NVD with a CVSS 3.0 score of 4.4.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-2987

CVE-2016-2987 is an IBM information disclosure issue in CLM applications. According to NVD, an attacker with low privileges and network access could cause some administrative deployment parameters to be shown, creating a limited confidentiality exposure rather than an integrity or availability impact.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-2939

CVE-2016-2939 is a cross-site scripting vulnerability in IBM iNotes, also reflected in IBM Domino CPE coverage in NVD. The issue was published on 2017-02-01 and is rated medium severity (CVSS 6.1). Because the flaw allows JavaScript to run inside the Web UI, an attacker can alter page behavior and potentially expose credentials within a trusted session.

MEDIUM IBM CVE published 2017-02-01

CVE-2016-2938

CVE-2016-2938 is a medium-severity cross-site scripting issue in IBM iNotes, with NVD also listing affected IBM Domino and IBM iNotes releases. The flaw allows arbitrary JavaScript to be embedded in the web UI, which can alter page behavior and may disclose credentials within a trusted session.

CRITICAL IBM CVE published 2017-02-01

CVE-2016-2908

CVE-2016-2908 is a critical XML external entity (XXE) issue reported in IBM software. According to the NVD description, a remote attacker could abuse XML parsing to read arbitrary files on the system or trigger a denial of service. The NVD record was published on 2017-02-01 and later modified on 2026-05-13.

HIGH IBM CVE published 2017-02-01

CVE-2016-0396

CVE-2016-0396 describes a command-injection weakness in IBM software that could let a user, under special circumstances, run commands with more privilege than intended. NVD rates the issue 8.1 (HIGH) and maps it to IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5. IBM’s advisory and a third-party bulletin were referenced in the NVD record, indicating patch guidance was available at disclosure time.

LOW IBM CVE published 2017-02-01

CVE-2016-0394

CVE-2016-0394 is a low-severity local vulnerability in IBM Integration Bus and WebSphere Message Broker. NVD describes it as incorrect permissions on an object that could let a local attacker manipulate certain files. Because the attack requires local access and the impact is limited to integrity, it is best treated as a patch-cycle issue rather than an emergency response.

LOW IBM CVE published 2017-02-01

CVE-2016-0297

CVE-2016-0297 is a low-severity information disclosure issue in IBM endpoint management software where a missing HTTP Strict-Transport-Security (HSTS) header could let a network attacker use man-in-the-middle techniques to obtain sensitive information. NVD assigns this issue CVSS 3.0 3.7 (Low) with confidentiality impact only.

LOW IBM CVE published 2017-02-01

CVE-2016-0296

CVE-2016-0296 describes an information disclosure issue in IBM Tivoli Endpoint Manager - Mobile Device Management, where potentially sensitive data can be stored in log files accessible to a local user. The NVD record maps the affected product family to IBM BigFix Platform versions 9.0, 9.1, 9.2, and 9.5. Because the issue requires local access and impacts confidentiality only, the published severity is l [truncated]