cbcvebase.

Ibm Kenexa Lms vulnerabilities

11 known vulnerabilities affecting ibm/kenexa_lms.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM6LOW1

Vulnerabilities

Page 1 of 1
CVE-2016-8932P3HIGHCVSS 8.8v4.1v4.2+6 more2017-02-01
CVE-2016-8932 [HIGH] CWE-284 CVE-2016-8932: IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow t IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
nvd
CVE-2016-8931P3HIGHCVSS 8.8v4.1v4.2+6 more2017-02-01
CVE-2016-8931 [HIGH] CWE-284 CVE-2016-8931: IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow t IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
nvd
CVE-2016-8930P3HIGHCVSS 7.6v4.1v4.2+6 more2017-02-01
CVE-2016-8930 [HIGH] CWE-89 CVE-2016-8930: IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-craft IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
nvd
CVE-2016-8928P3HIGHCVSS 7.6v4.1v4.2+6 more2017-02-01
CVE-2016-8928 [HIGH] CWE-89 CVE-2016-8928: IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-craft IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
nvd
CVE-2016-8933P3MEDIUMCVSS 6.5v4.1v4.2+6 more2017-02-01
CVE-2016-8933 [MEDIUM] CWE-22 CVE-2016-8933: IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An atta IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
nvd
CVE-2016-5941P3MEDIUMCVSS 5.7v4.1v4.2+6 more2017-02-01
CVE-2016-5941 [MEDIUM] CWE-22 CVE-2016-5941: IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An atta IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
nvd
CVE-2016-8929P4MEDIUMCVSS 5.4v4.1v4.2+6 more2017-02-01
CVE-2016-8929 [MEDIUM] CWE-89 CVE-2016-8929: IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-craft IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
nvd
CVE-2016-5942P4MEDIUMCVSS 5.4v4.1v4.2+6 more2017-02-01
CVE-2016-5942 [MEDIUM] CWE-79 CVE-2016-5942: IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to em IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-8935P4MEDIUMCVSS 5.4v4.1v4.2+4 more2017-03-31
CVE-2016-8935 [MEDIUM] CWE-79 CVE-2016-8935: IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site s IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999483.
nvd
CVE-2016-5940P4MEDIUMCVSS 5.4v4.1v4.2+6 more2017-02-01
CVE-2016-5940 [MEDIUM] CWE-79 CVE-2016-5940: IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to em IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-5938P4LOWCVSS 3.3v4.1v4.2+6 more2017-02-01
CVE-2016-5938 [LOW] CWE-200 CVE-2016-5938: IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on t IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system.
nvd
Ibm Kenexa Lms vulnerabilities | cvebase