CVE-2014-0961
https://notcve.org/view.php?id=CVE-2014-0961
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de CSRF en IBM Tivoli Identity Manager (ITIM) 5.0 anterior a 5.0.0.15 y 5.1 anterior a 5.1.0.15 y IBM Security Identity Manager (ISIM) 6.0 anterior a 6.0.0.2 permite a usuarios remotos autenticados secuestrar la autenticación de usuarios arbitrarios para solicitudes que insertan secuencias de XSS. • http://secunia.com/advisories/59080 http://www-01.ibm.com/support/docview.wss?uid=swg21674754 http://www.securityfocus.com/bid/67909 https://exchange.xforce.ibmcloud.com/vulnerabilities/92747 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2009-3262
https://notcve.org/view.php?id=CVE-2009-3262
Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the last name field in a profile. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Self Service UI (SSUI) en IBM Tivoli Identity Manager (ITIM) v5.0.0.5 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML de forma arbitraria a través de el campo "last name" en un perfil. • http://secunia.com/advisories/36511 http://securitytracker.com/id?1022837 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ54747 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •