Mobilefirst Platform Foundation
IBM · 3 CVEs
CVE-2020-4229
HIGH
IBM Worklight/MobileFoundation 8.0.0.0 does not properly invalidate session cookies when a user logs out of a session,…
Jun 5, 2020
CVE-2020-4226
HIGH
IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to inf…
May 27, 2020
CVE-2017-1772
MEDIUM
IBM Worklight (IBM MobileFirst Platform Foundation 6.3, 7.0, 7.1, and 8.0) is vulnerable to cross-site scripting. This…
Apr 4, 2018
CVE-2017-1500
MEDIUM
A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of…
Aug 1, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-4229 | IBM Worklight/MobileFoundation 8.0.0.0 does not properly invalidate session cookies when a user logs out of a session, which could allow another user to gain u… | HIGH | 0.85% | Jun 5, 2020 |
| CVE-2020-4226 | IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to information disclosure if unauthorized part… | HIGH | 1.29% | May 27, 2020 |
| CVE-2017-1772 | IBM Worklight (IBM MobileFirst Platform Foundation 6.3, 7.0, 7.1, and 8.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi… | MEDIUM | 1.27% | Apr 4, 2018 |
| CVE-2017-1500 | A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of IBM Worklight Framework 6.1, 6.2, 6.3,… | MEDIUM | 0.78% | Aug 1, 2017 |
Showing 1 to 3 of 3 CVEs