Connections
Vendor:
First CVE: Apr 27, 2013 · Active for 13 years
45
Total CVEs
More Total CVEs than 98% of tracked products
7.5
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Connections over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2013
13 years ago
Most Recent CVE
Jun 14, 2019
2,600 days ago
CVE Severity & Scoring
Connections45 CVEs
9%
87%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network42 (93.3%)
Unknown2 (4.4%)
Physical1 (2.2%)
Adjacent Network0 (0.0%)
Attack Complexity
Low41 (91.1%)
High2 (4.4%)
Unknown2 (4.4%)
User Interaction
None13 (28.9%)
Unknown2 (4.4%)
Required30 (66.7%)
Privileges Required
Low37 (82.2%)
High0 (0.0%)
None6 (13.3%)
Unknown2 (4.4%)
Top CVEs
Signals from CVEs in this product scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3007HIGH Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentic | Sep 26, 2016 | 8.8 | 26 | NO | NO |
CVE-2016-2999MEDIUM IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack. | Sep 26, 2016 | 6.5 | 23 | NO | NO |
CVE-2017-1748MEDIUM IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web | Jun 4, 2018 | 6.1 | 21 | NO | NO |
CVE-2017-1498MEDIUM IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality | Dec 7, 2017 | 5.4 | 21 | NO | NO |
CVE-2016-2955MEDIUM Cross-site scripting (XSS) vulnerability in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecifi | Dec 1, 2016 | 5.4 | 21 | NO | NO |
CVE-2016-3008MEDIUM Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML | Sep 1, 2016 | 5.4 | 21 | NO | NO |
CVE-2019-4403MEDIUM IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality | Jun 14, 2019 | 5.4 | 20 | NO | NO |
CVE-2018-1791MEDIUM IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation of a request property. By submitting suitable payloads, an | Sep 14, 2018 | 4.9 | 20 | NO | NO |
CVE-2016-5932MEDIUM IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the int | Mar 1, 2017 | 5.4 | 20 | NO | NO |
CVE-2016-3010MEDIUM Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to | Sep 1, 2016 | 5.4 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (45 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (45 CVEs).
Media Mentions
Signals from CVEs in this product scope (45 CVEs).
Top CNAs Publishing CVEs For Connections
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.0 | 7 | 5.3 | 1.0% | 0 | 0 |
| 5.5.0.0 | 22 | 5.3 | 0.7% | 0 | 0 |
| 5.5 | 4 | 5.0 | 0.9% | 0 | 0 |
| 5.0.0.0 | 30 | 5.1 | 0.8% | 0 | 0 |
| 5.0 | 9 | 5.5 | 0.8% | 0 | 0 |
| 4.5.0.0 | 26 | 5.0 | 0.8% | 0 | 0 |
| 4.5 | 6 | 5.8 | 0.7% | 0 | 0 |
| 4.0.0.0 | 25 | 5.0 | 0.8% | 0 | 0 |
| 4.0 | 6 | 5.8 | 0.7% | 0 | 0 |
| 3.0.1.0 | 1 | 6.0 | 0.5% | 0 | 0 |
| 3.0.0.0 | 1 | 6.0 | 0.5% | 0 | 0 |
| 2.5.0.3 | 1 | 6.0 | 0.5% | 0 | 0 |
| 2.5.0.2 | 1 | 6.0 | 0.5% | 0 | 0 |
| 2.5.0.1 | 1 | 6.0 | 0.5% | 0 | 0 |
| 2.5.0.0 | 1 | 6.0 | 0.5% | 0 | 0 |
| 2.0.1.1 | 1 | 6.0 | 0.5% | 0 | 0 |
| 2.0.1.0 | 1 | 6.0 | 0.5% | 0 | 0 |
| 2.0.0.0 | 1 | 6.0 | 0.5% | 0 | 0 |
| 1.0.2.0 | 1 | 6.0 | 0.5% | 0 | 0 |
| 1.0.1.0 | 1 | 6.0 | 0.5% | 0 | 0 |