Skip to main content

Vendor/product archive

ibm / kenexa_lcms_premier CVEs

Beta · best-effort

11 CVEs tagged to ibm / kenexa_lcms_premier0 Critical, 5 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2017-1143

Published Mar 27, 2017

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Securit…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1142

Published Mar 27, 2017

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9994

Published Mar 1, 2017

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to v…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9993

Published Mar 1, 2017

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to v…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9992

Published Mar 1, 2017

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to v…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5952

Published Feb 1, 2017

IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5951

Published Feb 1, 2017

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5950

Published Feb 1, 2017

IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5949

Published Feb 1, 2017

IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5948

Published Feb 1, 2017

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5937

Published Feb 1, 2017

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1