CVE-2018-1921
- EPSS 0.16%
- Veröffentlicht 17.07.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:00:36
IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w...
CVE-2019-4384
- EPSS 0.36%
- Veröffentlicht 19.06.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:43:32
IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 16217...
CVE-2018-1941
- EPSS 0.03%
- Veröffentlicht 05.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:00:38
IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-Force ID: 153382.
CVE-2016-9749
- EPSS 0.04%
- Veröffentlicht 09.11.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:42
IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass security due to lack of input validation. IBM X-Force ID: 120206.
CVE-2017-1114
- EPSS 0.16%
- Veröffentlicht 07.09.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:21:20
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr...
CVE-2017-1115
- EPSS 0.09%
- Veröffentlicht 07.09.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:21:21
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 121...
CVE-2017-1116
- EPSS 0.21%
- Veröffentlicht 27.04.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:21:21
IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.
CVE-2016-0265
- EPSS 0.16%
- Veröffentlicht 01.02.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security...