Ibm Kenexa Lms vulnerabilities

11 known vulnerabilities affecting ibm/kenexa_lms.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM6LOW1

Vulnerabilities

Page 1 of 1
CVE-2016-8935MEDIUMCVSS 5.4v4.1v4.2+4 more2017-03-31
CVE-2016-8935 [MEDIUM] CWE-79 CVE-2016-8935: IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site s IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999483.
nvd
CVE-2016-8932HIGHCVSS 8.8v4.1v4.2+6 more2017-02-01
CVE-2016-8932 [HIGH] CWE-284 CVE-2016-8932: IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow t IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
nvd
CVE-2016-8930HIGHCVSS 7.6v4.1v4.2+6 more2017-02-01
CVE-2016-8930 [HIGH] CWE-89 CVE-2016-8930: IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-craft IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
nvd
CVE-2016-8931HIGHCVSS 8.8v4.1v4.2+6 more2017-02-01
CVE-2016-8931 [HIGH] CWE-284 CVE-2016-8931: IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow t IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
nvd
CVE-2016-8928HIGHCVSS 7.6v4.1v4.2+6 more2017-02-01
CVE-2016-8928 [HIGH] CWE-89 CVE-2016-8928: IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-craft IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
nvd
CVE-2016-8933MEDIUMCVSS 6.5v4.1v4.2+6 more2017-02-01
CVE-2016-8933 [MEDIUM] CWE-22 CVE-2016-8933: IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An atta IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
nvd
CVE-2016-5941MEDIUMCVSS 5.7v4.1v4.2+6 more2017-02-01
CVE-2016-5941 [MEDIUM] CWE-22 CVE-2016-5941: IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An atta IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
nvd
CVE-2016-8929MEDIUMCVSS 5.4v4.1v4.2+6 more2017-02-01
CVE-2016-8929 [MEDIUM] CWE-89 CVE-2016-8929: IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-craft IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
nvd
CVE-2016-5942MEDIUMCVSS 5.4v4.1v4.2+6 more2017-02-01
CVE-2016-5942 [MEDIUM] CWE-79 CVE-2016-5942: IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to em IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-5940MEDIUMCVSS 5.4v4.1v4.2+6 more2017-02-01
CVE-2016-5940 [MEDIUM] CWE-79 CVE-2016-5940: IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to em IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-5938LOWCVSS 3.3v4.1v4.2+6 more2017-02-01
CVE-2016-5938 [LOW] CWE-200 CVE-2016-5938: IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on t IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system.
nvd