3 results (0.007 seconds)

CVSS: 7.5EPSS: 1%CPEs: 10EXPL: 0

Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack." • http://secunia.com/advisories/11761 http://www-1.ibm.com/support/docview.wss?uid=swg21168762 http://www.securityfocus.com/bid/10449 https://exchange.xforce.ibmcloud.com/vulnerabilities/16315 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e. WebSeal en IBM Tivoli SecureWay Policy Director 3.8 permite a atacantes remotos causar la denegación de servicios (caida) mediante una URL que finalice con .. • http://www.securityfocus.com/archive/1/245283 http://www.securityfocus.com/bid/3685 •

CVSS: 5.0EPSS: 0%CPEs: 4EXPL: 0

Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings. • ftp://ftp.tivoli.com/support/patches/patches_3.7.1/3.7.1-POL-0003/3.7.1-POL-0003.README http://archives.neohapsis.com/archives/bugtraq/2001-07/0497.html http://www-1.ibm.com/support/search.wss?rs=0&q=IY18152&apar=only http://www.osvdb.org/1908 http://www.securityfocus.com/bid/3080 https://exchange.xforce.ibmcloud.com/vulnerabilities/6884 •