
CVE-2025-23227 – IBM Tivoli Application Dependency Discovery Manager cross-site scripting
https://notcve.org/view.php?id=CVE-2025-23227
23 Jan 2025 — IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. • https://www.ibm.com/support/pages/node/7181334 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-47142 – IBM Tivoli Application Dependency Discovery Manager privilege escalation
https://notcve.org/view.php?id=CVE-2023-47142
02 Feb 2024 — IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267. IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 a 7.3.0.10 podría permitir que un atacante en la red local de la organización escale sus privilegios debido a un acceso API no autorizado. ID de IBM X-Force: 270267. • https://exchange.xforce.ibmcloud.com/vulnerabilities/270267 • CWE-264: Permissions, Privileges, and Access Controls CWE-863: Incorrect Authorization •

CVE-2023-47144 – IBM Tivoli Application Dependency Discovery Manager cross-site scripting
https://notcve.org/view.php?id=CVE-2023-47144
02 Feb 2024 — IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 270271. IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 a 7.3.0.10 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a los usuarios incrustar código JavaScrip... • https://exchange.xforce.ibmcloud.com/vulnerabilities/270271 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-47143 – IBM Tivoli Application Dependency Discovery Manager HOST header injection
https://notcve.org/view.php?id=CVE-2023-47143
02 Feb 2024 — IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 270270. IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 a 7.3.0.10 es vulnerable a la inyección de encabezados HTTP, causada por una validación incorr... • https://exchange.xforce.ibmcloud.com/vulnerabilities/270270 • CWE-116: Improper Encoding or Escaping of Output CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax •

CVE-2018-1675
https://notcve.org/view.php?id=CVE-2018-1675
04 Feb 2019 — IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are configured to use TADDM. IBM X-Force ID: 145110. IBM Tivoli Application Dependency Discovery Manager 7.2.2 y 7.3 podría exponer hashes de contraseña almacenados en la memoria del sistema en los sistemas objetivo que están configurados para emplear TADDM. IBM X-Force ID: 145110. • http://www.ibm.com/support/docview.wss?uid=ibm10742403 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-1455
https://notcve.org/view.php?id=CVE-2018-1455
15 Aug 2018 — IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 11029. IBM Tivoli Application Dependency Discovery Manager en sus versiones 7.2.2 y 7.3 es vulnerable a ataques Cross-Site Request Forgery (CSRF). Esto podría permitir que un atacante ejecute acciones maliciosas y no autorizadas transmitidas desde un usuario en... • http://www.securityfocus.com/bid/105135 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2013-3017
https://notcve.org/view.php?id=CVE-2013-3017
09 Jul 2018 — IBM Tivoli Application Dependency Discovery Manager (TADDM) before 7.2.1.5 and 7.2.x before 7.2.2 make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging support for weak SSL ciphers. IBM X-Force ID: 84353. IBM Tivoli Application Dependency Discovery Manager (TADDM) en versiones anteriores a la 7.2.1.5 y 7.2.x anteriores a la 7.2.2 facilita que los atacantes remotos sorteen los mecanismo de protección criptográfica aprovechando que soporta cifrados SSL débiles. IBM X-... • https://exchange.xforce.ibmcloud.com/vulnerabilities/84353 • CWE-310: Cryptographic Issues •

CVE-2013-3023
https://notcve.org/view.php?id=CVE-2013-3023
24 May 2018 — IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used. IBM X-Force ID: 84361. IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 y de la versión 7.2.0 a la 7.2.1.4 podría permitir que atacantes remotos obtengan información sensible sobre credenciales Tomcat rastreando la web en busca de una sesión en la que se e... • http://www-01.ibm.com/support/docview.wss?uid=swg21672388 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2013-3018
https://notcve.org/view.php?id=CVE-2013-3018
24 May 2018 — The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct request, as demonstrated by happyaxis.jsp. IBM X-Force ID: 84354. La aplicación web AXIS en deploy-tomcat/axis en IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 y de la versión 7.2.0 a la 7.2.1.4 permite que atacantes remotos obtengan información sensible de configuración medi... • http://www-01.ibm.com/support/docview.wss?uid=swg21672403 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2013-4040
https://notcve.org/view.php?id=CVE-2013-4040
01 May 2018 — IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2.x before 7.2.1.5 and 7.2.x before 7.2.2.0 on Unix use weak permissions (755) for unspecified configuration and log files, which allows local users to obtain sensitive information by reading the files. IBM X-Force ID: 86176. IBM Tivoli Application Dependency Discovery Manager (TADDM) en versiones 7.1.2.x anteriores a la 7.2.1.5 y versiones 7.2.x anteriores a la 7.2.2.0 en Unix emplea permisos débiles (755) para archivos de configuración y de r... • https://exchange.xforce.ibmcloud.com/vulnerabilities/86176 • CWE-275: Permission Issues •