Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 18.104.22.168 and Endpoint Manager for Software Use Analysis 9 before 22.214.171.124 allows remote attackers to hijack the authentication of arbitrary users via vectors involving a FRAME element.
IBM License Metric Tool 9 before 126.96.36.199 and Endpoint Manager for Software Use Analysis 9 before 188.8.131.52 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.
The log viewer in IBM Workload Deployer 3.1 before 184.108.40.206 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document.
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 220.127.116.11 iFix10, 6.0.5 before 18.104.22.168, and 22.214.171.124a before 126.96.36.199 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (hea...