Page 13 of 78 results (0.004 seconds)

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142650. IBM API Connect desde la versión 5.0.0.0 hasta la 5.0.8.3 podría permitir que un atacante remoto obtenga información sensible, provocado por la imposibilidad de habilitar correctamente HTTP Strict Transport Security. Un atacante podría explotar esta vulnerabilidad para obtener información sensible empleando técnicas man-in-the-Middle (MitM). • https://exchange.xforce.ibmcloud.com/vulnerabilities/142650 https://www-prd-trops.events.ibm.com/node/715299 https://www.ibm.com/support/pages/node/715299 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430. IBM API Connect desde la versión 5.0.0.0 hasta la 5.0.8.2 no actualiza correctamente SESSIONID con cada petición, lo que podría permitir al usuario obtener el ID en ataques posteriores contra el sistema. IBM X-Force ID: 142430. • http://www.ibm.com/support/docview.wss?uid=swg22015978 https://exchange.xforce.ibmcloud.com/vulnerabilities/142430 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 0

IBM API Connect 5.0.8.1 and 5.0.8.2 could allow a user to get access to internal environment and sensitive API details to which they are not authorized. IBM X-Force ID: 140399. IBM API Connect 5.0.8.1 y 5.0.8.2 podría permitir que un usuario consiga acceso a detalles sensibles del entorno interno y de la API para los cuales no tiene acceso. IBM X-Force ID: 140399. • http://www.ibm.com/support/docview.wss?uid=swg22015968 https://exchange.xforce.ibmcloud.com/vulnerabilities/140399 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

IBM API Connect 5.0.0.0 through 5.0.8.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139226. IBM API Connect, de la versión 5.0.0.0 hasta la 5.0.8.2, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=swg22013058 http://www.securityfocus.com/bid/104027 https://exchange.xforce.ibmcloud.com/vulnerabilities/139226 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

IBM API Connect 5.0.0.0 through 5.0.8.2 is impacted by generated LoopBack APIs for a Model using the BelongsTo/HasMany relationship allowing unauthorized modification of information. IBM X-Force ID: 138213. IBM API Connect, de la versión 5.0.0.0 hasta la 5.0.8.2, se ha visto impactado por las API LoopBack generadas para un Model que emplea la relación BelongsTo/HasMany, lo que permite la modificación no autorizada de la información. IBM X-Force ID: 138213. • http://www.ibm.com/support/docview.wss?uid=swg22013531 http://www.securityfocus.com/bid/104026 https://exchange.xforce.ibmcloud.com/vulnerabilities/138213 •