CVE-2022-22425
https://notcve.org/view.php?id=CVE-2022-22425
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598." "IBM InfoSphere Information Server 11.7 es potencialmente vulnerable a la inyección CSV. Un atacante remoto podría ejecutar comandos arbitrarios en el sistema, causados por una validación incorrecta del contenido del archivo csv. • https://www.ibm.com/support/pages/node/6829953 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •
CVE-2022-22442
https://notcve.org/view.php?id=CVE-2022-22442
"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427." "IBM InfoSphere Information Server 11.7 podría permitir que un usuario autenticado acceda a información restringida a usuarios con privilegios elevados debido a controles de acceso inadecuados. IBM X-Force ID: 224427". • https://www.ibm.com/support/pages/node/6829325 •
CVE-2022-40235
https://notcve.org/view.php?id=CVE-2022-40235
"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input validation. IBM X-Force ID: 235725." "IBM InfoSphere Information Server 11.7 podría permitir a un usuario provocar una Denegación de Servicio (DoS) al eliminar la capacidad de ejecutar trabajos debido a una validación de entrada incorrecta. IBM X-Force ID: 235725". • https://www.ibm.com/support/pages/node/6829369 • CWE-20: Improper Input Validation •
CVE-2022-30615
https://notcve.org/view.php?id=CVE-2022-30615
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592. "IBM InfoSphere Information Server 11.7 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría conducir a la divulgación de credenciales dentro de una sesión confiable. • https://www.ibm.com/support/pages/node/6829311 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-40747
https://notcve.org/view.php?id=CVE-2022-40747
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584." "IBM InfoSphere Information Server 11.7 es vulnerable a un ataque de XML External Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría aprovechar esta vulnerabilidad para exponer información confidencial o consumir recursos de memoria. • https://www.ibm.com/support/pages/node/6829373 • CWE-611: Improper Restriction of XML External Entity Reference •