VendorsIBMconnectionsall versions
Vulnerabilities

IBM Connections

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

45CVEs
CVE-2013-0569
Cross-site scripting (XSS) vulnerability in the Communities component in IBM Connections 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2013-04-27 · Modified
4.3EPSS 0.011
CVE-2016-0308
IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images.
Published 2017-02-08 · Modified
4.3EPSS 0.007
CVE-2016-3009
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page.
Published 2016-11-30 · Modified
3.5EPSS 0.005
CVE-2016-2998
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update data.
Published 2016-09-01 · Modified
3.5EPSS 0.004
CVE-2016-3002
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.
Published 2016-11-30 · Modified
2.1EPSS 0.003
← Prev2 / 2