Skip to main content

Vendor/product archive

ibm / infosphere_biginsights CVEs

Beta · best-effort

20 CVEs tagged to ibm / infosphere_biginsights0 Critical, 3 High, 13 Medium, 4 Low, 0 Unrated.

CVE-2014-4782

Published Apr 20, 2018

IBM InfoSphere BigInsights 2.1.2 allows remote authenticated users to discover SMTP server credentials via vectors related to the Alert management service. IBM X-Force ID: 95029.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1336

Published Dec 7, 2017

IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1554

Published Nov 1, 2017

IBM Infosphere BigInsights 4.2.0 and 4.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remot…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1553

Published Nov 1, 2017

IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1552

Published Nov 1, 2017

IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this v…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5020

Published Jan 2, 2016

The Big SQL component in IBM InfoSphere BigInsights 3.0, 3.0.0.1, 3.0.0.2, and 4.0 allows remote authenticated users to bypass intended access restrictions and truncate arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1947

Published Dec 31, 2015

Untrusted search path vulnerability in IBM InfoSphere BigInsights 3.0, 3.0.0.1, 3.0.0.2, and 4.0, when a DB2 database is used, allows local users to gain privileges via a Trojan h…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1836

Published Dec 21, 2015

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1772

Published Dec 21, 2015

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mish…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4940

Published Nov 8, 2015

Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain s…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-4928

Published Nov 8, 2015

Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to ob…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1889

Published Apr 22, 2015

The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4781

Published Feb 13, 2015

The alert module in IBM InfoSphere BigInsights 2.1.2 and 3.x before 3.0.0.2 allows remote attackers to obtain sensitive Alert management-services API information via a network-tra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0905

Published Aug 17, 2014

IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which makes it easier for remote attackers to capture this cooki…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-3993

Published Jul 7, 2014

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted param…

CVSS 6.5 · Medium
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2013-3998

Published Mar 26, 2014

CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to inject arbitra…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-3997

Published Mar 26, 2014

Open redirect vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to redirect users…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3996

Published Aug 6, 2013

IBM InfoSphere BigInsights 1.1 through 2.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3995

Published Aug 6, 2013

Cross-site scripting (XSS) vulnerability in IBM InfoSphere BigInsights 1.1 through 2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vec…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-3992

Published Aug 6, 2013

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere BigInsights 2.0 through 2.1 allows remote authenticated users to hijack the authentication of unspecified victims…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1