2 results (0.023 seconds)

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 164555. IBM Security Access Manager for Enterprise Single Sign-On versión 8.2.2, es vulnerable a un ataque de tipo XML External Entity (XXE) cuando se procesa datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información confidencial o consumir recursos de la memoria. • http://www.ibm.com/support/docview.wss?uid=ibm10996716 https://exchange.xforce.ibmcloud.com/vulnerabilities/164555 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 134913. IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 no establece el atributo secure en los tokens de autorización o cookies de sesión. • http://www.ibm.com/support/docview.wss?uid=ibm10726017 https://exchange.xforce.ibmcloud.com/vulnerabilities/134913 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •