CVE-2018-1388
https://notcve.org/view.php?id=CVE-2018-1388
GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212. GSKit V7 podría revelar información del canal lateral mediante discrepancias entre rellenos PKCS#1 válidos e inválidos. IBM X-Force ID: 138212. • http://www.ibm.com/support/docview.wss?uid=swg22013022 http://www.securityfocus.com/bid/103698 https://exchange.xforce.ibmcloud.com/vulnerabilities/138212 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-1612
https://notcve.org/view.php?id=CVE-2017-1612
IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' user. IBM X-Force ID: 132953. El módulo de rastreo de servicios IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0 y 9.0 podría emplearse para ejecutar código no fiable bajo un usuario "mqm". IBM X-Force ID: 132953. • http://www.ibm.com/support/docview.wss?uid=swg22009918 http://www.securityfocus.com/bid/102479 http://www.securitytracker.com/id/1040175 https://exchange.xforce.ibmcloud.com/vulnerabilities/132953 •
CVE-2016-3013
https://notcve.org/view.php?id=CVE-2016-3013
IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling. IBM Reference #: 1998661. IBM WebSphere MQ 8.0 podría permitir a un usuario autenticado bloquear el canal MQ debido al manejo incorrecto de la conversión de datos. IBM Reference #: 1998661. • http://www.ibm.com/support/docview.wss?uid=swg21998661 http://www.securityfocus.com/bid/96394 • CWE-19: Data Processing Errors •
CVE-2016-3052
https://notcve.org/view.php?id=CVE-2016-3052
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man in the middle techniques. Bajo configuraciones no estándar, WebSphere MQ de IBM, puede enviar datos de contraseña en texto sin cifrar por medio de la red. Estos datos podrían ser interceptados usando técnicas de tipo man in the middle. • http://www.ibm.com/support/docview.wss?uid=swg21998660 http://www.securityfocus.com/bid/96400 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-0360
https://notcve.org/view.php?id=CVE-2016-0360
IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457. El cliente de IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0 y 9.0 provee clases que deserializan objetos desde fuentes no confiables que podrían permitir a un usuario malicioso ejecutar código Java arbitrario añadiendo clases vulnerables a la ruta de clase. IBM Referencia #: 1983457. • http://www-01.ibm.com/support/docview.wss?uid=swg21983457 http://www.securityfocus.com/bid/95317 http://www.securitytracker.com/id/1037561 • CWE-502: Deserialization of Untrusted Data •