CVE-2023-47142 – IBM Tivoli Application Dependency Discovery Manager privilege escalation
https://notcve.org/view.php?id=CVE-2023-47142
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267. IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 a 7.3.0.10 podría permitir que un atacante en la red local de la organización escale sus privilegios debido a un acceso API no autorizado. ID de IBM X-Force: 270267. • https://exchange.xforce.ibmcloud.com/vulnerabilities/270267 https://www.ibm.com/support/pages/node/7105139 • CWE-264: Permissions, Privileges, and Access Controls CWE-863: Incorrect Authorization •
CVE-2023-47144 – IBM Tivoli Application Dependency Discovery Manager cross-site scripting
https://notcve.org/view.php?id=CVE-2023-47144
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 270271. IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 a 7.3.0.10 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría conducir a la divulgación de credenciales dentro de una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/270271 https://www.ibm.com/support/pages/node/7105139 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-47143 – IBM Tivoli Application Dependency Discovery Manager HOST header injection
https://notcve.org/view.php?id=CVE-2023-47143
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 270270. IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 a 7.3.0.10 es vulnerable a la inyección de encabezados HTTP, causada por una validación incorrecta de la entrada por parte de los encabezados HOST. Esto podría permitir que un atacante realice varios ataques contra el sistema vulnerable, incluido cross-site scripting, envenenamiento de caché o secuestro de sesión. • https://exchange.xforce.ibmcloud.com/vulnerabilities/270270 https://www.ibm.com/support/pages/node/7105139 • CWE-116: Improper Encoding or Escaping of Output CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax •
CVE-2018-1675
https://notcve.org/view.php?id=CVE-2018-1675
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are configured to use TADDM. IBM X-Force ID: 145110. IBM Tivoli Application Dependency Discovery Manager 7.2.2 y 7.3 podría exponer hashes de contraseña almacenados en la memoria del sistema en los sistemas objetivo que están configurados para emplear TADDM. IBM X-Force ID: 145110. • http://www.ibm.com/support/docview.wss?uid=ibm10742403 https://exchange.xforce.ibmcloud.com/vulnerabilities/145110 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-8926
https://notcve.org/view.php?id=CVE-2016-8926
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539. IBM Tivoli Application Dependency Discovery Manager 7.2.2 y 7.3 podría permitir a un atacante remoto leer archivos del sistema o datos que estén restringidos a usuarios autorizados. IBM X-Force ID: 118539. • http://www.ibm.com/support/docview.wss?uid=swg22001579&myns=swgtiv&mynp=OCSSPLFC&mync=E&cm_sp=swgtiv-_-OCSSPLFC-_-E • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •