CVE-2015-7490
https://notcve.org/view.php?id=CVE-2015-7490
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie. IBM InfoSphere Information Server 8.5 hasta la versión FP3, 8.7 hasta la versión FP2, 9.1 hasta la versión 9.1.2.0, 11.3 hasta la versión 11.3.1.2 y 11.5 permite a usuarios remotos autentificados eludir las restricciones destinadas al acceso a través de una cookie modificada. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR54787 http://www-01.ibm.com/support/docview.wss?uid=swg21975827 http://www.securitytracker.com/id/1035125 • CWE-284: Improper Access Control •
CVE-2015-1901
https://notcve.org/view.php?id=CVE-2015-1901
The installer in IBM InfoSphere Information Server 8.5 through 11.3 before 11.3.1.2 allows local users to obtain sensitive information via unspecified commands. El instalador en IBM InfoSphere Information Server 8.5 hasta 11.3 anterior a 11.3.1.2 permite a usuarios locales obtener información sensible a través de comandos no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR52549 http://www-01.ibm.com/support/docview.wss?uid=swg21701436 http://www.securityfocus.com/bid/75162 http://www.securitytracker.com/id/1032633 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2015-0180
https://notcve.org/view.php?id=CVE-2015-0180
The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modification via unspecified vectors. Connector Migration Tool en IBM InfoSphere Information Server 8.1 hasta 11.3 permite a usuarios remotos autenticados evadir las restricciones sobre la creación y modificación de empleo a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR51665 http://www-01.ibm.com/support/docview.wss?uid=swg21697306 • CWE-284: Improper Access Control •
CVE-2014-0933
https://notcve.org/view.php?id=CVE-2014-0933
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Information Server Metadata Workbench 8.1 through 9.1 allows remote attackers to hijack the authentication of arbitrary users. Vulnerabilidad de CSRF en IBM InfoSphere Information Server Metadata Workbench 8.1 hasta 9.1 permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR49605 http://www-01.ibm.com/support/docview.wss?uid=swg21671141 https://exchange.xforce.ibmcloud.com/vulnerabilities/92273 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2013-4059
https://notcve.org/view.php?id=CVE-2013-4059
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified interfaces. Múltiples vulnerabilidades de XSS en el servidor de IBM InfoSphere Information 8.x hasta 8.5 FP3, 8.7.x hasta 8.7 FP2 y 9.1.x hasta 9.1.2.0 permiten a atacantes remotos inyectar script Web o HTML arbitrarios a través de interfaces no especificadas. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR48815 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49200 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49206 http://www-01.ibm.com/support/docview.wss?uid=swg21666684 http://www.securityfocus.com/bid/66151 https://exchange.xforce.ibmcloud.com/vulnerabilities/86548 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •