
CVE-2018-1652
https://notcve.org/view.php?id=CVE-2018-1652
11 Dec 2018 — IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724. IBM DataPower Gateway desde la versión 7.1.0.0 hasta la 7.1.0.19, desde la 7.2.0.0 hasta la 7.2.0.16, desde la 7.5.0.0 hasta la 7.5.0.10, desde la 7.5.1.0 hasta l... • https://exchange.xforce.ibmcloud.com/vulnerabilities/144724 • CWE-20: Improper Input Validation •

CVE-2018-1429
https://notcve.org/view.php?id=CVE-2018-1429
23 Mar 2018 — IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139077. IBM MQ Appliance en sus versiones 9.0.1, 9.0.2, 9.0.3 y 9.0.4 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de u... • http://www.ibm.com/support/docview.wss?uid=swg22014046 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •