IBM / Connections
45 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-4403 | IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i… | MEDIUM | 5.4 | Jun 14, 2019 |
| CVE-2018-1896 | IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-Force ID:… | MEDIUM | 5.4 | Dec 7, 2018 |
| CVE-2018-1935 | IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request error messages. IBM X-Force ID: 153315. | MEDIUM | 4.3 | Dec 6, 2018 |
| CVE-2018-1791 | IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation of a request property. By submitting s… | MEDIUM | 4.9 | Sep 14, 2018 |
| CVE-2017-1748 | IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a s… | MEDIUM | 6.8 | Jun 4, 2018 |
| CVE-2015-7461 | XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denia… | MEDIUM | 6.5 | Mar 20, 2018 |
| CVE-2015-7460 | Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web s… | MEDIUM | 5.4 | Mar 20, 2018 |
| CVE-2015-7459 | Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web s… | MEDIUM | 5.4 | Mar 20, 2018 |
| CVE-2015-7458 | Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web s… | MEDIUM | 5.4 | Mar 20, 2018 |
| CVE-2017-1682 | IBM Connections 4.0, 4.5, 5.0, 5.5, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We… | MEDIUM | 5.4 | Feb 14, 2018 |
| CVE-2017-1683 | IBM Connections Engagement Center 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t… | MEDIUM | 5.4 | Dec 11, 2017 |
| CVE-2017-1613 | IBM Connections 6.0 could allow an unauthenticated remote attacker to gain unauthenticated or unauthorized access to non-sensitive Engagement Center template d… | MEDIUM | 5.3 | Dec 11, 2017 |
| CVE-2017-1498 | IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i… | MEDIUM | 5.4 | Dec 7, 2017 |
| CVE-2016-5932 | IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… | MEDIUM | 5.4 | Mar 1, 2017 |
| CVE-2016-0310 | IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. | MEDIUM | 5.4 | Feb 8, 2017 |
| CVE-2016-0308 | IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images. | MEDIUM | 4.3 | Feb 8, 2017 |
| CVE-2016-0307 | IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses. | MEDIUM | 4.3 | Feb 8, 2017 |
| CVE-2016-0305 | IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability… | MEDIUM | 5.4 | Feb 8, 2017 |
| CVE-2016-2955 | Cross-site scripting (XSS) vulnerability in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script… | MEDIUM | 5.4 | Dec 1, 2016 |
| CVE-2016-3009 | Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hi… | LOW | 3.5 | Nov 30, 2016 |
| CVE-2016-3004 | Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hi… | MEDIUM | 4.6 | Nov 30, 2016 |
| CVE-2016-3002 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached da… | LOW | 2.1 | Nov 30, 2016 |
| CVE-2016-2958 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic"… | MEDIUM | 4.3 | Nov 30, 2016 |
| CVE-2016-2957 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace… | MEDIUM | 4.3 | Nov 30, 2016 |
| CVE-2016-2953 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext informat… | LOW | 3.7 | Nov 30, 2016 |
Showing 1 to 25 of 45 CVEs