CVE-2013-5426
https://notcve.org/view.php?id=CVE-2013-5426
Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors. Vulnerabilidad de fijación de sesión en IBM InfoSphere Master Data Management - Collaborative Edition 10.x anteriores a 10.1 IF5 y 11.0 anteriores a IF1 e InfoSphere Master Data Management Server para Product Information Management 9.x anteriores a 9.1 IF11 permite a usuarios autenticados remotamente secuestrar sesiones web a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21660082 https://exchange.xforce.ibmcloud.com/vulnerabilities/87535 • CWE-287: Improper Authentication •
CVE-2013-4036
https://notcve.org/view.php?id=CVE-2013-4036
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en IBM InfoSphere Master Data Management Server para Product Information Management 9.x anterior a la versión 9.1 FP13, e IBM InfoSphere Master Data Management - Collaborative Edition 10.x anterior a la versión 10.1 FP7 y 11.0 anterior a FP2, permite a usuarios remotos autenticados inyectar script web o HTML arbitrario a través de vectores sin especificar. • http://www-01.ibm.com/support/docview.wss?uid=swg21656857 https://exchange.xforce.ibmcloud.com/vulnerabilities/81482 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-0478
https://notcve.org/view.php?id=CVE-2013-0478
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Cross-site scripting (XSS) en IBM InfoSphere Master Data Management - Collaborative Edition v10.0 y v10.1 antes de FP1 y Iter Data Management Server for Product Information Management v6.0, v9.0, y v9.1 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML a través vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21624952 https://exchange.xforce.ibmcloud.com/vulnerabilities/81482 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-0477
https://notcve.org/view.php?id=CVE-2013-0477
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allow remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en IBM InfoSphere Master Data Management - Collaborative Edition v10.0 y v10.1 antes de FP1 y InfoSphere Master Server Gestión de Datos de Información de Gestión de Productos v6.0, v9.0, v9.1 y permitir a usuarios remotos autenticados inyectar contenido, y llevar a cabo ataques de phising, a través de vectores sin especificar. • http://www-01.ibm.com/support/docview.wss?uid=swg21624952 https://exchange.xforce.ibmcloud.com/vulnerabilities/81481 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •