CVE-2016-6000
published 2017-02-01CVE-2016-6000: IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…
PriorityP423medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.71%
49.3th percentile
IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7rxq-7pcm-pg2j: IBM TRIRIGA Application Platform is vulnerable to cross-site scripting
ghsa_unreviewed·2022-05-17
CVE-2016-6000 [MEDIUM] CWE-79 GHSA-7rxq-7pcm-pg2j: IBM TRIRIGA Application Platform is vulnerable to cross-site scripting
IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Cisco
Cisco IOS XR Software for NCS 6000 Series Devices OSPF Packet Processing Denial of Service Vulnerability
vendor_cisco·2016-09-14·CVSS 5.0
CVE-2016-1433 [MEDIUM] CWE-399 Cisco IOS XR Software for NCS 6000 Series Devices OSPF Packet Processing Denial of Service Vulnerability
Cisco IOS XR Software for NCS 6000 Series Devices OSPF Packet Processing Denial of Service Vulnerability
A vulnerability in the OSPFv3 processing of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 6000 Series devices could allow an unauthenticated, remote attacker to cause a reload of the OSPFv3 process and result in a limited denial of service (DoS) condition on an affected device.
The vulnerability is due to insufficient logic in the processing of crafted OSPFv3 packets. An attacker could exploit this vulnerability by sending crafted OSPFv3 packets to be processed by an affected device. An exploit could allow the attacker to cause a reload of the OSPFv3 process and cause a limited DoS condition on the affected device.
Cisco has released software updates that address t
Cisco
Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
vendor_cisco·2016-07-13·CVSS 7.8
CVE-2016-1426 [HIGH] Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
A vulnerability in the management of system timer resources in Cisco IOS XR for Cisco Network Convergence System 6000 (NCS 6000) Series Routers could allow an unauthenticated, remote attacker to cause a leak of system timer resources, leading to a nonoperational state and an eventual reload of the Route Processor (RP) on the affected platform.
The vulnerability is due to improper management of system timer resources. An attacker could exploit this vulnerability by sending a number of Secure Shell (SSH), Secure Copy Protocol (SCP), and Secure FTP (SFTP) management connections to an affected device. An exploit could allow the attacker to cause a leak of system timer resources, leading to a nonoperational state and
Cisco
Cisco IOS XR Software for NCS 6000 Series Devices OSPF Packet Processing Denial of Service Vulnerability
vendor_cisco
CVE-2016-1433 Cisco IOS XR Software for NCS 6000 Series Devices OSPF Packet Processing Denial of Service Vulnerability
CVE-2016-1433: Cisco IOS XR Software for NCS 6000 Series Devices OSPF Packet Processing Denial of Service Vulnerability
A vulnerability in the OSPFv3 processing of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 6000 Series devices could allow an unauthenticated, remote attacker to cause a reload of the OSPFv3 process and result in a limited denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient logic in the processing of crafted OSPFv3 packets. An attacker could exploit this vulnerability by sending crafted OSPFv3 packets to be processed by an affected device. An exploit could allow the attacker to cause a reload of the OSPFv3 process and cause a limited DoS condition on the affected device. Cisco has released software updates th
Cisco
Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
vendor_cisco
CVE-2016-1426 Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
CVE-2016-1426: Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
A vulnerability in the management of system timer resources in Cisco IOS XR for Cisco Network Convergence System 6000 (NCS 6000) Series Routers could allow an unauthenticated, remote attacker to cause a leak of system timer resources, leading to a nonoperational state and an eventual reload of the Route Processor (RP) on the affected platform. The vulnerability is due to improper management of system timer resources. An attacker could exploit this vulnerability by sending a number of Secure Shell (SSH), Secure Copy Protocol (SCP), and Secure FTP (SFTP) management connections to an affected device. An exploit could allow the attacker to cause a leak of system timer resources, leading to a nonoperation
No detection rules found.
No writeups or analysis indexed.
2017-02-01
Published