CVE-2014-3092
https://notcve.org/view.php?id=CVE-2014-3092
IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. IBM Jazz Team Server, utilizado en Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x anterior a 3.0.1.6 iFix 3, 4.x anterior a 4.0.7, y 5.x anterior a 5.0.1; y otros productos Rational, no configura el indicador de seguridad para la cookie de la sesión en una sesión https, lo que facilita a atacantes remotos capturar esta cookie mediante la intercepción de su transmisión dentro de una sesión http. • http://www-01.ibm.com/support/docview.wss?uid=swg21682787 https://exchange.xforce.ibmcloud.com/vulnerabilities/94258 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-3037
https://notcve.org/view.php?id=CVE-2014-3037
Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager before 4.0.7 and 5.x before 5.0.1, Rational Software Architect Design Manager before 4.0.7 and 5.x before 5.0.1, and Rational Rhapsody Design Manager before 4.0.7 and 5.x before 5.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de CSRF en IBM Configuration Management Application (también conocido como VVC) en IBM Rational Engineering Lifecycle Manager anterior a 4.0.7 y 5.x anterior a 5.0.1, Rational Software Architect Design Manager anterior a 4.0.7 y 5.x anterior a 5.0.1, y Rational Rhapsody Design Manager anterior a 4.0.7 y 5.x anterior a 5.0.1 permite a usuarios remotos autenticados secuestrar la autenticación de usuarios arbitrarios para solicitudes que insertan secuencias de XSS. • http://secunia.com/advisories/60649 http://secunia.com/advisories/61071 http://www-01.ibm.com/support/docview.wss?uid=swg21682120 http://www.securityfocus.com/bid/69658 https://exchange.xforce.ibmcloud.com/vulnerabilities/93303 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2014-0947
https://notcve.org/view.php?id=CVE-2014-0947
Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrary code via a crafted update site. Vulnerabilidad no especificada en el servidor en IBM Rational Software Architect Design Manager 4.0.6 permite a usuarios remotos autenticados ejecutar código arbitrario a través de un sitio de actualizaciones manipulado. • http://www-01.ibm.com/support/docview.wss?uid=swg21678323 https://exchange.xforce.ibmcloud.com/vulnerabilities/92620 •
CVE-2014-0948
https://notcve.org/view.php?id=CVE-2014-0948
Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody Design Manager 3.x and 4.x before 4.0.7 allows remote authenticated users to execute arbitrary code via a crafted ZIP archive. Vulnerabilidad no especificada en IBM Rational Software Architect Design Manager y Rational Rhapsody Design Manager 3.x y 4.x anterior a 4.0.7 permite a usuarios remotos autenticados ejecutar código arbitrario a través de un archivo ZIP manipulado. • http://www-01.ibm.com/support/docview.wss?uid=swg21678323 https://exchange.xforce.ibmcloud.com/vulnerabilities/92621 •
CVE-2013-5459
https://notcve.org/view.php?id=CVE-2013-5459
Unspecified vulnerability in IBM Rational Software Architect (RSA) Design Manager and Rational Rhapsody Design Manager 3.x through 3.0.1 and 4.x before 4.0.6 allows remote authenticated users to modify data by leveraging improper parameter checking. Vulnerabilidad no especificada en IBM Rational Software Architect (RSA) Design Manager y Rational Rhapsody Design Manager 3.x hasta 3.0.1 y 4.x anterior a 4.0.6 permite a usuarios remotos autenticados modificar datos mediante el aprovechamiento de la comprobación indebida de parámetros. • http://www-01.ibm.com/support/docview.wss?uid=swg21664531 https://exchange.xforce.ibmcloud.com/vulnerabilities/84773 •