2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6115 | — | — | 4.0% | Feb 1, 2017 | IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a bu... |
| CVE-2016-6110 | — | — | 0.3% | Feb 1, 2017 | IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local u... |
| CVE-2016-6068 | — | — | 1.4% | Feb 1, 2017 | IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResour... |
| CVE-2016-6001 | — | — | 0.6% | Feb 1, 2017 | IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design in... |
| CVE-2016-5953 | — | — | 0.8% | Feb 1, 2017 | IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain v... |
| CVE-2016-5942 | — | — | 0.6% | Feb 1, 2017 | IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2016-5941 | — | — | 1.6% | Feb 1, 2017 | IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a sp... |
| CVE-2016-5940 | — | — | 0.5% | Feb 1, 2017 | IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2016-5938 | — | — | 0.3% | Feb 1, 2017 | IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system. |
| CVE-2016-5881 | — | — | 1.0% | Feb 1, 2017 | IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in ... |
| CVE-2016-2992 | — | — | 0.5% | Feb 1, 2017 | IBM Infosphere BigInsights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2016-2942 | — | — | 0.8% | Feb 1, 2017 | IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a... |
| CVE-2016-2941 | — | — | 0.4% | Feb 1, 2017 | IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including pa... |
| CVE-2016-2924 | — | — | 0.7% | Feb 1, 2017 | IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. ... |
| CVE-2016-0320 | — | — | 0.6% | Feb 1, 2017 | IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly... |
| CVE-2016-0218 | — | — | 0.7% | Feb 1, 2017 | IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper val... |
| CVE-2016-0217 | — | — | 0.7% | Feb 1, 2017 | IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by impro... |
| CVE-2016-8967 | — | — | 0.3% | Feb 1, 2017 | IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user. |
| CVE-2016-6117 | — | — | 1.6% | Feb 1, 2017 | IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive info... |
| CVE-2016-6105 | — | — | 2.1% | Feb 1, 2017 | IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functiona... |
| CVE-2016-9731 | — | — | 0.5% | Feb 1, 2017 | IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2016-8981 | — | — | 0.3% | Feb 1, 2017 | IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system. |
| CVE-2016-8980 | — | — | 1.5% | Feb 1, 2017 | IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error whe... |
| CVE-2016-8966 | — | — | 1.2% | Feb 1, 2017 | IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly... |
| CVE-2016-8961 | — | — | 0.9% | Feb 1, 2017 | IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By per... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now