Ibm Connections vulnerabilities
46 known vulnerabilities affecting ibm/connections.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM40LOW4
Vulnerabilities
Page 3 of 3
CVE-2016-3000P4MEDIUMCVSS 4.3v4.0.0.0v4.5.0.0+2 more2016-09-26
CVE-2016-3000 [MEDIUM] CWE-20 CVE-2016-3000: The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows r
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.
nvd
CVE-2013-0569P4MEDIUMCVSS 4.3v4.5.0.02013-04-27
CVE-2013-0569 [MEDIUM] CWE-79 CVE-2013-0569: Cross-site scripting (XSS) vulnerability in the Communities component in IBM Connections 4.5 allows
Cross-site scripting (XSS) vulnerability in the Communities component in IBM Connections 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2016-3009P4LOWCVSS 3.5v4.0.0.0v4.5.0.0+1 more2016-11-30
CVE-2016-3009 [LOW] CWE-352 CVE-2016-3009: Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5,
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page.
nvd
CVE-2016-2998P4LOWCVSS 3.5v4.0.0.0v4.5.0.0+2 more2016-09-01
CVE-2016-2998 [LOW] CWE-352 CVE-2016-2998: Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5,
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update data.
nvd
CVE-2016-2953P4LOWCVSS 3.7v4.0.0.0v4.5.0.0+1 more2016-11-30
CVE-2016-2953 [LOW] CWE-310 CVE-2016-2953: IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which all
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
nvd
CVE-2016-3002P4LOWCVSS 2.1v4.0.0.0v4.5.0.0+1 more2016-11-30
CVE-2016-3002 [LOW] CWE-200 CVE-2016-3002: IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate att
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.
nvd
← Previous3 / 3