Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 18.104.22.168 and Endpoint Manager for Software Use Analysis 9 before 22.214.171.124 allows remote attackers to hijack the authentication of arbitrary users via vectors involving a FRAME element.
IBM License Metric Tool 9 before 126.96.36.199 and Endpoint Manager for Software Use Analysis 9 before 188.8.131.52 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.
The log viewer in IBM Workload Deployer 3.1 before 184.108.40.206 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document.
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 220.127.116.11 iFix10, 6.0.5 before 18.104.22.168, and 22.214.171.124a before 126.96.36.199 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Common Inventory Technology (CIT) before 188.8.131.520 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a cr...