12 results (0.015 seconds)

CVSS: 7.5EPSS: 0%CPEs: 34EXPL: 0

IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 128605. IBM Security Access Manager Appliance 8.0.0 hasta 8.0.1.6 y 9.0.0 hasta la 9.0.3.1 emplea algoritmos criptográficos más débiles de lo esperado que podrían permitir que un atacante descifre información altamente sensible. IBM X-Force ID: 128605. • http://www.ibm.com/support/docview.wss?uid=swg22012268 https://exchange.xforce.ibmcloud.com/vulnerabilities/128605 • CWE-326: Inadequate Encryption Strength •

CVSS: 3.3EPSS: 0%CPEs: 8EXPL: 0

IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613. La versión 9.0.0 de IBM Security Access Manager Appliance permite que las páginas web se almacenen localmente, lo que permite que sean leídas por otro usuario en el sistema. IBM X-Force ID: 128613. • http://www.ibm.com/support/docview.wss?uid=swg22012323 http://www.securityfocus.com/bid/102502 http://www.securitytracker.com/id/1040172 https://exchange.xforce.ibmcloud.com/vulnerabilities/128613 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.1EPSS: 0%CPEs: 33EXPL: 0

IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 130676. IBM Security Access Manager Appliance en sus versiones 8.0.0 y 9.0.0 podría permitir que un atacante remoto lleve a cabo ataques de phishing empleando un ataque de redirección abierta. • http://www.ibm.com/support/docview.wss?uid=swg22008936 http://www.securityfocus.com/bid/102509 http://www.securitytracker.com/id/1040169 https://exchange.xforce.ibmcloud.com/vulnerabilities/130676 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 9.1EPSS: 0%CPEs: 21EXPL: 0

IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service. IBM Single Sign On para Bluemix podrían permitir a un atacante remoto obtener información sensible, provocado por un error de entidad externa XML (XXE) al procesar datos XML por el analizador XML. Un atacante remoto podría explotar esta vulnerabilidad para leer archivos arbitrarios del sistema o provocar una denegación de servicio. • http://www.ibm.com/support/docview.wss?uid=swg21995531 http://www.securityfocus.com/bid/95295 http://www.securitytracker.com/id/1038506 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 4.0EPSS: 0%CPEs: 21EXPL: 0

IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system. IBM Security Access Manager para Web permite que las páginas web se almacenen localmente y que puedan ser leídas por otro usuario del sistema. • http://www.ibm.com/support/docview.wss?uid=swg21995340 http://www.securityfocus.com/bid/96132 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •