CVE-2014-0961
https://notcve.org/view.php?id=CVE-2014-0961
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de CSRF en IBM Tivoli Identity Manager (ITIM) 5.0 anterior a 5.0.0.15 y 5.1 anterior a 5.1.0.15 y IBM Security Identity Manager (ISIM) 6.0 anterior a 6.0.0.2 permite a usuarios remotos autenticados secuestrar la autenticación de usuarios arbitrarios para solicitudes que insertan secuencias de XSS. • http://secunia.com/advisories/59080 http://www-01.ibm.com/support/docview.wss?uid=swg21674754 http://www.securityfocus.com/bid/67909 https://exchange.xforce.ibmcloud.com/vulnerabilities/92747 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2009-2316
https://notcve.org/view.php?id=CVE-2009-2316
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. NOTE: it was later reported that 4.6.0 is also affected by the first vector. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en IBM Tivoli Identity Manager (ITIM) v5.0, permiten a atacantes remotos inyectar secuencias de comandos Web o HTML de su elección al introducir una URL no especificada en (1) la interfaz del propio servicio UI o (2) la interfaz de la consola. • http://osvdb.org/55550 http://osvdb.org/55551 http://secunia.com/advisories/35696 http://secunia.com/advisories/36119 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ54310 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ54311 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55518 http://www-01.ibm.com/support/docview.wss?uid=swg24023640 http://www-01.ibm.com/support/docview.wss? • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •