Monthly Archive: September 2018

CVE-2018-1669

IBM DataPower Gateway 7.1.0.0 – 7.1.0.23, 7.2.0.0 – 7.2.0.21, 7.5.0.0 – 7.5.0.16, 7.5.1.0 – 7.5.1.15, 7.5.2.0 – 7.5.2.15, and 7.6.0.0 – 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 – 7.7.1.2 are vulnerable...

CVE-2018-1664

IBM DataPower Gateway 7.1.0.0 – 7.1.0.23, 7.2.0.0 – 7.2.0.21, 7.5.0.0 – 7.5.0.16, 7.5.1.0 – 7.5.1.15, 7.5.2.0 – 7.5.2.15, and 7.6.0.0 – 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 – 7.7.1.2 echoing of...

CVE-2018-1659

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...

CVE-2018-1607

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to...

CVE-2018-15965

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution. Date published :...