CVE-2016-0338
https://notcve.org/view.php?id=CVE-2016-0338
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a configuration file or (2) examining a process. IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 hasta la versión 7.0.1.1 en versiones anteriores a 7.0.1-ISS-SIM-FP0003 permite a usuarios locales descubrir contraseñas en texto plano (1) leyendo un archivo de configuración o (2) examinando un proceso. • http://www-01.ibm.com/support/docview.wss?uid=swg21985736 http://www.securitytracker.com/id/1036255 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-0357
https://notcve.org/view.php?id=CVE-2016-0357
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web site. IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 hasta la versión 7.0.1.1 en versiones anteriores a 7.0.1-ISS-SIM-FP0003 permite a atacantes remotos llevar a cabo ataques de clickjacking a través de un sitio web manipulado. • http://www-01.ibm.com/support/docview.wss?uid=swg21985736 http://www.securityfocus.com/bid/87528 http://www.securitytracker.com/id/1036255 • CWE-284: Improper Access Control •
CVE-2014-8923
https://notcve.org/view.php?id=CVE-2014-8923
The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows local users to obtain sensitive information by reading a file. El adaptador (1) IBM Tivoli Identity Manager Active Directory en versiones anteriores a 5.1.24 y el adaptador (2) IBM Security Identity Manager Active Directory en versiones anteriores a 6.0.14 para IBM Security Identity Manager en Windows, cuando ciertos niveles de registro y rastreo son configurados, almacena la contraseña de administrador en un archivo de registro, lo que permite a usuarios locales obtener información sensible leyendo un archivo. • http://www-01.ibm.com/support/docview.wss?uid=swg21699902 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-6168
https://notcve.org/view.php?id=CVE-2014-6168
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad CSRF en IBM Security Identity Manager 5.1 anterior a 5.1.0.15 IF0056 permite a usuarios remotos autenticados secuestrar la autenticación de usuarios arbitrarios para peticiones que insertan secuencias XSS. • http://www-01.ibm.com/support/docview.wss?uid=swg21692907 https://exchange.xforce.ibmcloud.com/vulnerabilities/97752 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2014-6105
https://notcve.org/view.php?id=CVE-2014-6105
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspecified vectors. IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF14 permite a atacantes remotos llevar a cabo ataques de clickjacking a través de vectores no especificados. • http://secunia.com/advisories/62363 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66496 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66624 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66635 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66637 http://www-01.ibm.com/support/docview.wss? • CWE-20: Improper Input Validation •