|
211761
|
7.7 |
HIGH
Network
|
ibm
|
mashups_center
|
The Lotus Mashups component in IBM Mashup Center 3.0.0.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an XML external entity declaration in conjunction with an…
|
CWE-399
Resource Management Errors
|
CVE-2015-7400
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211762
|
5.4 |
MEDIUM
Network
|
ibm
|
maximo_for_transportation maximo_for_utilities maximo_asset_management smartcloud_control_desk maximo_for_life_sciences maximo_asset_management_essentials maximo_for_nuclear_power
|
The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Con…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7396
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211763
|
7.0 |
HIGH
Local
|
ibm
|
packaging_utility installation_manager
|
consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7442
|
2024-11-21 11:36 |
2016-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211764
|
5.4 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7402
|
2024-11-21 11:36 |
2016-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211765
|
5.4 |
MEDIUM
Network
|
ibm
|
maximo_for_transportation maximo_for_utilities maximo_asset_management smartcloud_control_desk maximo_for_life_sciences maximo_asset_management_essentials maximo_for_nuclear_power
|
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7451
|
2024-11-21 11:36 |
2016-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211766
|
8.5 |
HIGH
Network
|
ibm
|
spectrum_protect_for_virtual_environments spectrum_protect_snapshot
|
The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.4 and…
|
CWE-200
Information Exposure
|
CVE-2015-7429
|
2024-11-21 11:36 |
2016-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211767
|
6.5 |
MEDIUM
Network
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows remote authenticated users to discover object-storage admin passwords via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-7456
|
2024-11-21 11:36 |
2016-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211768
|
5.4 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.6 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified field.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7409
|
2024-11-21 11:36 |
2016-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211769
|
4.3 |
MEDIUM
Network
|
ibm
|
b2b_advanced_communications multi-enterprise_integration_gateway
|
IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.x before 1.0.0.4, when guest access is configured, allow remote authenticated users to obtain sensitive …
|
CWE-200
Information Exposure
|
CVE-2015-7445
|
2024-11-21 11:36 |
2016-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211770
|
3.7 |
LOW
Network
|
ibm
|
mq_appliance_m2000
|
Unspecified vulnerability in GSKit on IBM MQ M2000 appliances before 8.0.0.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2015-7420.
|
CWE-200
Information Exposure
|
CVE-2015-7421
|
2024-11-21 11:36 |
2016-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|