Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.7
CVE-2016-5941
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request c…
Kenexa Lms
Patch available
MEDIUM 5.5
CVE-2016-2941
IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by…
Urbancode Deploy
Mitigation only
MEDIUM 5.5
CVE-2016-8963
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
License Metric Tool
after 9.2
MEDIUM 5.4
CVE-2016-0217
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-suppli…
Cognos Analytics
Patch available
MEDIUM 5.4
CVE-2016-0218
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied inpu…
Cognos Business Intelligence
Patch available
MEDIUM 5.4
CVE-2016-2924
IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could explo…
Biginsights
Patch available
MEDIUM 5.4
CVE-2016-2992
IBM Infosphere BigInsights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…
Biginsights
Patch available
MEDIUM 5.4
CVE-2016-5940
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …
Kenexa Lms
Patch available
MEDIUM 5.4
CVE-2016-5942
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …
Kenexa Lms
Patch available
MEDIUM 5.4
CVE-2016-8929
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker…
Kenexa Lms
Patch available
HIGH 8.2
CVE-2016-6105
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users…
Security Key Lifecycle Manager
Patch available
MEDIUM 5.5
CVE-2016-0371
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.
Tivoli Storage Manager
after 7.1.6.2
MEDIUM 5.5
CVE-2016-8967
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
License Metric Tool
Mitigation only
MEDIUM 5.3
CVE-2016-6117
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.
Security Key Lifecycle Manager
Patch available
HIGH 8.1
CVE-2016-8980
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remo…
License Metric Tool
Mitigation only
MEDIUM 6.1
CVE-2016-8961
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a s…
License Metric Tool
after 9.2
MEDIUM 5.9
CVE-2016-8966
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport…
License Metric Tool
Mitigation only
MEDIUM 5.5
CVE-2016-8981
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
License Metric Tool
Mitigation only
MEDIUM 5.4
CVE-2016-8943
IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…
Spectrum Control
Patch available
MEDIUM 5.4
CVE-2016-9731
IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …
Business Process Manager
Patch available
CRITICAL 10.0
CVE-2016-6082
IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker cou…
Bigfix Platform
Patch available
CRITICAL 9.8
CVE-2016-6090
IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performing of unauthorized administra…
Websphere Commerce
after 8.0.1.8
HIGH 8.8
CVE-2016-6124
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arb…
Kenexa Lms On Cloud
Mitigation only
HIGH 8.8
CVE-2016-8921
IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vul…
Filenet Workplace Xt
Mitigation only
HIGH 8.8
CVE-2016-8941
IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…
Spectrum Control
Patch available
HIGH 8.1
CVE-2016-6059
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da…
Infosphere Datastage
Patch available
HIGH 7.8
CVE-2016-6065
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.
Security Guardium
Patch available
MEDIUM 6.5
CVE-2016-6084
IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request.
Bigfix Platform
Patch available
MEDIUM 6.5
CVE-2016-6085
IBM BigFix Platform could allow an attacker on the local network to crash the BES and relay servers.
Bigfix Platform
Patch available
MEDIUM 6.5
CVE-2016-6126
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall…
Kenexa Lms On Cloud
Mitigation only