Skip to main content

Vendor/product archive

ibm / connections CVEs

Beta · best-effort

45 CVEs tagged to ibm / connections0 Critical, 2 High, 39 Medium, 4 Low, 0 Unrated.

CVE-2016-3006

Published Sep 26, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3003

Published Sep 26, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3001

Published Sep 26, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3000

Published Sep 26, 2016

The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2999

Published Sep 26, 2016

IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3010

Published Sep 1, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3008

Published Sep 1, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTM…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3005

Published Sep 1, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2998

Published Sep 1, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2997

Published Sep 1, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2995

Published Sep 1, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2956

Published Sep 1, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTM…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2954

Published Sep 1, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTM…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0322

Published Jun 30, 2016

Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1 allows remote authenticated users to inject arbit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5038

Published Jan 3, 2016

IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote atta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5037

Published Jan 3, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5036

Published Jan 3, 2016

Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5035

Published Jan 3, 2016

Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0929

Published Jun 8, 2014

Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows remote authenticated users to hijack the authentication of…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0569

Published Apr 27, 2013

Cross-site scripting (XSS) vulnerability in the Communities component in IBM Connections 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-45 of 45 CVEsPage 2 of 2