Ibm Algo One vulnerabilities
16 known vulnerabilities affecting ibm/algo_one.
Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM10LOW5
Vulnerabilities
Page 1 of 1
CVE-2017-1154MEDIUMCVSS 6.5v4.9.1v5.0.0+1 more2017-03-31
CVE-2017-1154 [MEDIUM] CWE-200 CVE-2017-1154: IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access t
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users. IBM Reference #: 1999892.
nvd
CVE-2017-1155MEDIUMCVSS 4.3v4.9.1v5.0.0+1 more2017-03-20
CVE-2017-1155 [MEDIUM] CWE-200 CVE-2017-1155: IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access t
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to another user's reports using a specially crafted HTTP request. IBM Reference #: 1999754.
nvd
CVE-2016-0390MEDIUMCVSS 5.4v4.9.1v5.0.0+1 more2016-05-15
CVE-2016-0390 [MEDIUM] CWE-79 CVE-2016-0390: Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.
Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-6304MEDIUMCVSS 4.0v4.9.12014-03-06
CVE-2013-6304 [MEDIUM] CWE-22 CVE-2013-6304: Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in
Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.
nvd
CVE-2013-6319MEDIUMCVSS 4.0v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-6319 [MEDIUM] CWE-264 CVE-2013-6319: IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Securi
IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to bypass intended access restrictions and read content via unspecified vectors.
nvd
CVE-2013-6302MEDIUMCVSS 6.5v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-6302 [MEDIUM] CWE-89 CVE-2013-6302: SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 throu
SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6331.
nvd
CVE-2013-6303MEDIUMCVSS 4.0v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-6303 [MEDIUM] CWE-22 CVE-2013-6303: Directory traversal vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0
Directory traversal vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to read arbitrary files via unspecified vectors.
nvd
CVE-2013-5468MEDIUMCVSS 5.0v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-5468 [MEDIUM] CWE-310 CVE-2013-5468: IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Securi
IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, does not encrypt login requests, which allows remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2013-6331MEDIUMCVSS 6.5v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-6331 [MEDIUM] CVE-2013-6331: SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 throu
SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6302.
nvd
CVE-2013-6318MEDIUMCVSS 4.3v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-6318 [MEDIUM] CWE-79 CVE-2013-6318: Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UD
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-6301LOWCVSS 3.5v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-6301 [LOW] CVE-2013-6301: Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UD
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013
nvd
CVE-2013-6299LOWCVSS 3.5v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-6299 [LOW] CWE-79 CVE-2013-6299: Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UD
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than C
nvd
CVE-2013-6320LOWCVSS 3.5v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-6320 [LOW] CVE-2013-6320: Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UD
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013
nvd
CVE-2013-6300LOWCVSS 3.5v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-6300 [LOW] CVE-2013-6300: Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UD
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013
nvd
CVE-2013-6333LOWCVSS 3.5v4.7.0v4.7.1+4 more2014-03-05
CVE-2013-6333 [LOW] CVE-2013-6333: Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UD
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013
nvd
CVE-2013-6332HIGHCVSS 8.5v4.7.0v4.7.1+4 more2014-02-06
CVE-2013-6332 [HIGH] CVE-2013-6332: Unrestricted file upload vulnerability in IBM Algo One UDS 4.7.0 through 5.0.0 allows remote authent
Unrestricted file upload vulnerability in IBM Algo One UDS 4.7.0 through 5.0.0 allows remote authenticated users to execute arbitrary code by uploading a .jsp file and then launching it.
nvd