Connections

Vendor:

First CVE: Apr 27, 2013 · Active for 13 years

45
Total CVEs
More Total CVEs than 98% of tracked products
7.5
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Connections over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2013
13 years ago
Most Recent CVE
Jun 14, 2019
2,600 days ago

CVE Severity & Scoring

Connections45 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network42 (93.3%)
Unknown2 (4.4%)
Physical1 (2.2%)
Adjacent Network0 (0.0%)
Attack Complexity
Low41 (91.1%)
High2 (4.4%)
Unknown2 (4.4%)
User Interaction
None13 (28.9%)
Unknown2 (4.4%)
Required30 (66.7%)
Privileges Required
Low37 (82.2%)
High0 (0.0%)
None6 (13.3%)
Unknown2 (4.4%)

Top CVEs

Signals from CVEs in this product scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentic
Sep 26, 20168.826NONO
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.
Sep 26, 20166.523NONO
IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web
Jun 4, 20186.121NONO
IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality
Dec 7, 20175.421NONO
Cross-site scripting (XSS) vulnerability in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecifi
Dec 1, 20165.421NONO
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML
Sep 1, 20165.421NONO
IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality
Jun 14, 20195.420NONO
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation of a request property. By submitting suitable payloads, an
Sep 14, 20184.920NONO
IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the int
Mar 1, 20175.420NONO
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to
Sep 1, 20165.420NONO

Exploit Exposure

Signals from CVEs in this product scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (45 CVEs).

Media Mentions

Signals from CVEs in this product scope (45 CVEs).

Top CNAs Publishing CVEs For Connections

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.075.31.0%00
5.5.0.0225.30.7%00
5.545.00.9%00
5.0.0.0305.10.8%00
5.095.50.8%00
4.5.0.0265.00.8%00
4.565.80.7%00
4.0.0.0255.00.8%00
4.065.80.7%00
3.0.1.016.00.5%00
3.0.0.016.00.5%00
2.5.0.316.00.5%00
2.5.0.216.00.5%00
2.5.0.116.00.5%00
2.5.0.016.00.5%00
2.0.1.116.00.5%00
2.0.1.016.00.5%00
2.0.0.016.00.5%00
1.0.2.016.00.5%00
1.0.1.016.00.5%00