CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2016-3029 HIGH

IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tra…

CVSS 8.8 EPSS 0.45% Feb 1, 2017
CVE-2016-3027 MEDIUM

IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A re…

CVSS 6.5 EPSS 1.31% Feb 1, 2017
CVE-2016-3024 MEDIUM

IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.

CVSS 4.0 EPSS 0.32% Feb 1, 2017
CVE-2016-3023 MEDIUM

IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.

CVSS 5.3 EPSS 1.13% Feb 1, 2017
CVE-2016-3022 MEDIUM

IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions.

CVSS 6.5 EPSS 1.72% Feb 1, 2017
CVE-2016-3021 LOW

IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP req…

CVSS 2.7 EPSS 1.03% Feb 1, 2017
CVE-2016-3017 HIGH

IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations.

CVSS 7.5 EPSS 2.22% Feb 1, 2017
CVE-2016-3016 MEDIUM

IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, whi…

CVSS 4.4 EPSS 0.35% Feb 1, 2017
CVE-2016-2908 CRITICAL

IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML d…

CVSS 9.1 EPSS 3.39% Feb 1, 2017
CVE-2014-6079 MEDIUM

Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x befor…

CVSS 4.3 EPSS 1.36% Oct 3, 2014
CVE-2014-4823 HIGH

The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Mana…

CVSS 10.0 EPSS 2.79% Oct 3, 2014
CVE-2014-7169 KEV CRITICAL

bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271)

CVSS 9.8 EPSS 99.94% Sep 25, 2014
CVE-2014-6271 KEV CRITICAL

bash: specially-crafted environment variables can be used to inject shell commands

CVSS 9.8 EPSS 100.00% Sep 24, 2014

Showing 1 to 13 CVEs · page 1