8 results (0.005 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805. IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11 y 3.0.12 es vulnerable a la falta de autorización y podría permitir que un usuario autenticado cargue complementos externos y ejecute código. ID de IBM X-Force: 238805. • https://exchange.xforce.ibmcloud.com/vulnerabilities/238805 https://www.ibm.com/support/pages/node/6844453 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-862: Missing Authorization •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they should not have access to. IBM X-Force ID: 186679. IBM Content Navigator versiones 3.0.7 y 3.0.8, podrían permitir a un usuario autenticado visualizar el contenido en memoria caché de otro usuario al que no debería tener acceso. IBM X-Force ID: 186679. • https://exchange.xforce.ibmcloud.com/vulnerabilities/186679 https://www.ibm.com/support/pages/node/6262423 •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters that could be stored in the IBM Content Navigator database. IBM X-Force ID: 183316. IBM Content Navigator versiones 3.0.7 y 3.0.8, es vulnerable a una comprobación de entrada inapropiada. Un administrador malicioso podría omitir la interfaz de usuario y enviar peticiones al servidor de IBM Content Navigator con caracteres ilegales que podrían ser almacenados en la base de datos de IBM Content Navigator. • https://exchange.xforce.ibmcloud.com/vulnerabilities/183316 https://www.ibm.com/support/pages/node/6262411 • CWE-20: Improper Input Validation •

CVSS: 5.4EPSS: 0%CPEs: 5EXPL: 0

IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141219. IBM Content Navigator, en sus versiones 2.0.3, 3.0.0, 3.0.1, 3.0.2 y 3.0.3 , es vulnerable a ataques de tipo Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=swg22015420 http://www.securityfocus.com/bid/104374 https://exchange.xforce.ibmcloud.com/vulnerabilities/141219 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 0

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452. IBM Content Navigator 2.0 y 3.0 es vulnerable a una inyección CSV (Comma Separated Value). Un atacante podría explotar esta vulnerabilidad para explotar otras vulnerabilidades en software de hojas de cálculo. • http://www.ibm.com/support/docview.wss?uid=swg22012674 https://exchange.xforce.ibmcloud.com/vulnerabilities/137452 •