
CVE-2018-1845
https://notcve.org/view.php?id=CVE-2018-1845
17 Jun 2019 — IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905. Las versiones 1.3, 11.5 y 11.7 de IBM InfoSphere Information Server son vulnerables a ataques de tipo XML External Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer info... • https://exchange.xforce.ibmcloud.com/vulnerabilities/150905 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2019-4257
https://notcve.org/view.php?id=CVE-2019-4257
06 Jun 2019 — IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive information in an error message may be used to conduct further attacks against the system. IBM X-Force ID: 159945. IBM InfoSphere Information Server 11.5 y 11.7 es afectado por una vulnerabilidad de revelación de información. La información confidencial en un mensaje de error puede ser usado para conducir mas ataques contra el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/159945 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2019-4238
https://notcve.org/view.php?id=CVE-2019-4238
25 Apr 2019 — IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159464. IBM InfoSphere Information Server versión 11.3, versión 11.5 y versión 11.7 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los usuarios introducir un código JavaScript arbit... • https://exchange.xforce.ibmcloud.com/vulnerabilities/159464 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1994
https://notcve.org/view.php?id=CVE-2018-1994
10 Apr 2019 — IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 154494. IBM InfoSphere Information Server versión 11.5 y versión 11.7 es vulnerable a la inyección SQL. Un atacante remoto podría enviar sentencias de SQL especialmente creadas, que podrían permitirle ver, agregar, modificar o eliminar información en la... • https://exchange.xforce.ibmcloud.com/vulnerabilities/154494 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2018-1917
https://notcve.org/view.php?id=CVE-2018-1917
02 Apr 2019 — IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784. IBM InfoSphere Information Server 11.3, 11.5 y 11.7 podría permitir que un usuario autenticado acceda a archivos JSP y divulgue información sensible. IBM X-Force ID: 152784. • http://www.securityfocus.com/bid/107688 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-1906
https://notcve.org/view.php?id=CVE-2018-1906
02 Apr 2019 — IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a specially crafted HTTP request. IBM X-Force ID: 152663. IBM InfoSphere Information Server 11.3, 11.5 y 11.7 podría permitir que un usuario autenticado descargue código utilizando una petición HTTP especialmente manipulada. IBM X-Force ID: 152663. • http://www.securityfocus.com/bid/107735 •

CVE-2018-1875
https://notcve.org/view.php?id=CVE-2018-1875
05 Mar 2019 — IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 151639.... • http://www.ibm.com/support/docview.wss?uid=ibm10738911 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2018-1899
https://notcve.org/view.php?id=CVE-2018-1899
05 Mar 2019 — IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528. IBM InfoSphere Information Server, en sus versiones 11.3, 11.5 y 11.7, podría permitir a un atacante modificar uno de los ajustes relacionados con InfoSphere Business Glossary Anywhere debido a un control de acceso incorrecto. IBM X-Force ID: 152528. • http://www.ibm.com/support/docview.wss?uid=ibm10744029 •

CVE-2018-1727
https://notcve.org/view.php?id=CVE-2018-1727
15 Feb 2019 — IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147630. Las versiones 9.1, 11.3, 11.5 y 11.7 de IBM InfoSphere Information Server son vulnerables a ataques de tipo XML External Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría explotar esta vulnerabilidad para e... • https://exchange.xforce.ibmcloud.com/vulnerabilities/147630 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2018-1895
https://notcve.org/view.php?id=CVE-2018-1895
15 Feb 2019 — IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152159. IBM InfoSphere Information Server 11.3, 11.5 y 11.7 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usua... • http://www.ibm.com/support/docview.wss?uid=ibm10744013 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •