15 results (0.015 seconds)

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

20 Mar 2018 — Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108356. Vulnerabilidad de Cross-Site Scripting (XSS) en las versiones 3.0.1.1 y anteriores, 4.0, 4.5 y versiones 5.0 anteriores a CR4 de 3.0.1.1 de IBM Connections permite a atacantes remotos inyectar scripts web o HTML arbitrarios utilizando vectores no especificados. IBM X-Force ID: 108356. • http://www-01.ibm.com/support/docview.wss?uid=swg21980518 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

20 Mar 2018 — Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108354. Vulnerabilidad de Cross-Site Scripting (XSS) en las versiones 3.0.1.1 y anteriores, 4.0, 4.5 y versiones 5.0 anteriores a CR4 de 3.0.1.1 de IBM Connections permite a atacantes remotos inyectar scripts web o HTML arbitrarios utilizando vectores no especificados. IBM X-Force ID: 108354. • http://www-01.ibm.com/support/docview.wss?uid=swg21980518 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

20 Mar 2018 — Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108355. Vulnerabilidad de Cross-Site Scripting (XSS) en las versiones 3.0.1.1 y anteriores, 4.0, 4.5 y versiones 5.0 anteriores a CR4 de 3.0.1.1 de IBM Connections permite a atacantes remotos inyectar scripts web o HTML arbitrarios utilizando vectores no especificados. IBM X-Force ID: 108355. • http://www-01.ibm.com/support/docview.wss?uid=swg21980518 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 0

20 Mar 2018 — XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denial of service (memory consumption) via crafted XML data. IBM X-Force ID: 108357. Vulnerabilidad de XEE (XML External Entity) en las versiones 3.0.1.1 y anteriores, 4.0, 4.5 y versiones 5.0 anteriores a CR4 de 3.0.1.1 de IBM Connections permite que usuarios autenticados remotos provoquen una denegación de servicio (consumo de memoria) mediante datos XML... • http://www-01.ibm.com/support/docview.wss?uid=swg21980518 • CWE-399: Resource Management Errors CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

26 Sep 2016 — IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack. IBM Connections 4.x hasta la versión 4.5 CR5, 5.0 en versiones anteriores a CR4 y 5.5 en versiones anteriores a CR1 permite a usuarios remotos autenticados obtener información sensible a través de un ataque de fuerza bruta no especificado. • http://www-01.ibm.com/support/docview.wss?uid=swg1LO89962 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.8EPSS: 0%CPEs: 4EXPL: 0

03 Jan 2016 — Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de CSRF en IBM Connections 3.x en versiones anteriores a 3.0.1.1 CR3, 4.0 en versiones anteriores a CR4, 4.5 en versiones anteriores a CR5 y 5.0 en versiones anteriores a CR3 permite a usuarios remotos autenticados secuestrar la aute... • http://www-01.ibm.com/support/docview.wss?uid=swg1LO87020 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

03 Jan 2016 — IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote attackers to cause a denial of service (CPU consumption and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. IBM Connections 3.x en versiones anteriores a 3.0.1.1 CR3, 4.0 en versiones anteriores a CR4, 4.5 en versiones anteriores a CR5 y 5.0 en versi... • http://www-01.ibm.com/support/docview.wss?uid=swg1LO87020 •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

03 Jan 2016 — Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-5036. Vulnerabilidad de XSS en IBM Connections 3.x en versiones anteriores a 3.0.1.1 CR3, 4.0 en versiones anteriores a CR4, 4.5 en versiones anteriores a CR5 y 5.0 en versiones anteriores a CR3 permite a usuarios remotos autenticados inyectar s... • http://www-01.ibm.com/support/docview.wss?uid=swg1LO87020 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

03 Jan 2016 — Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-5035. Vulnerabilidad de XSS en IBM Connections 3.x en versiones anteriores a 3.0.1.1 CR3, 4.0 en versiones anteriores a CR4, 4.5 en versiones anteriores a CR5 y 5.0 en versiones anteriores a CR3 permite a usuarios remotos autenticados inyectar s... • http://www-01.ibm.com/support/docview.wss?uid=swg1LO87020 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.0EPSS: 0%CPEs: 13EXPL: 0

08 Jun 2014 — Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that trigger follow actions. Vulnerabilidad de CSRF en el componente Profiles en IBM Connections hasta 3.0.1.1 CR3 permite a usuarios remotos autenticados secuestrar la autenticación de usuarios arbitrarios para solicitudes que provocan acciones 'seguir'. • http://secunia.com/advisories/59046 • CWE-352: Cross-Site Request Forgery (CSRF) •