Vulnerabilities (CVE)

Total 398522 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-5964 1 Ibm 1 Security Privileged Identity Manager 2026-06-17 5.0 MEDIUM 9.8 CRITICAL
IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
CVE-2016-5963 1 Ibm 1 Security Privileged Identity Manager Virtual Appliance 2026-06-17 6.5 MEDIUM 8.8 HIGH
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
CVE-2016-5960 1 Ibm 1 Security Privileged Identity Manager 2026-06-17 2.1 LOW 5.5 MEDIUM
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.
CVE-2016-5959 1 Ibm 1 Security Privileged Identity Manager 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136.
CVE-2016-5958 1 Ibm 1 Security Privileged Identity Manager 2026-06-17 5.0 MEDIUM 7.5 HIGH
IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information.
CVE-2016-5957 1 Ibm 1 Security Privileged Identity Manager Virtual Appliance 2026-06-17 5.0 MEDIUM 7.5 HIGH
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive information by leveraging a weak algorithm.
CVE-2016-5955 1 Ibm 1 Rational Doors Next Generation 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 6.0.2 before iFix004 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-5954 1 Ibm 1 Websphere Portal 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before CF12 allows remote authenticated users to cause a denial of service by uploading temporary files.
CVE-2016-5953 1 Ibm 1 Sterling Selling And Fulfillment Foundation 2026-06-17 4.3 MEDIUM 3.7 LOW
IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.
CVE-2016-5952 1 Ibm 1 Kenexa Lcms Premier 2026-06-17 6.5 MEDIUM 8.8 HIGH
IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2016-5951 1 Ibm 1 Kenexa Lcms Premier 2026-06-17 3.5 LOW 5.4 MEDIUM
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2016-5950 1 Ibm 1 Kenexa Lcms Premier 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user.
CVE-2016-5949 1 Ibm 1 Kenexa Lcms Premier 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request.
CVE-2016-5948 1 Ibm 1 Kenexa Lcms Premier 2026-06-17 3.5 LOW 5.4 MEDIUM
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2016-5947 1 Ibm 2 Spectrum Control, Tivoli Storage Productivity Center 2026-06-17 3.5 LOW 5.7 MEDIUM
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
CVE-2016-5946 1 Ibm 2 Spectrum Control, Tivoli Storage Productivity Center 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
CVE-2016-5945 1 Ibm 2 Spectrum Control, Tivoli Storage Productivity Center 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.
CVE-2016-5944 1 Ibm 2 Spectrum Control, Tivoli Storage Productivity Center 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.
CVE-2016-5943 1 Ibm 1 Spectrum Control 2026-06-17 5.5 MEDIUM 5.4 MEDIUM
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properties, via unspecified vectors.
CVE-2016-5942 1 Ibm 1 Kenexa Lms 2026-06-17 3.5 LOW 5.4 MEDIUM
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.