CVE-2017-1251
https://notcve.org/view.php?id=CVE-2017-1251
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. IBM X-Force ID: 124631. Una vulnerabilidad no revelada en aplicaciones CLM podría resultar en que algunos parámetros de implementación administrativa se muestren al atacante. IBM X-Force ID: 124631. • http://www.ibm.com/support/docview.wss?uid=swg22010682 https://exchange.xforce.ibmcloud.com/vulnerabilities/124631 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-9700
https://notcve.org/view.php?id=CVE-2016-9700
IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528. IBM Jazz Foundation podría permitir a un atacante autenticado obtener información confidencial de los rastreos de la pila de los mensajes de error. IBM X-Force ID: 119528. • http://www.ibm.com/support/docview.wss?uid=swg22005435 https://exchange.xforce.ibmcloud.com/vulnerabilities/119528 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-9973
https://notcve.org/view.php?id=CVE-2016-9973
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120209. Jazz Foundation de IBM es vulnerable a un problema de tipo cross-site-scripting. Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, lo que altera la funcionalidad deseada que puede conllevar a la divulgación de credenciales dentro de una sesión de segura. • http://www.ibm.com/support/docview.wss?uid=swg22004534 http://www.securityfocus.com/bid/99060 https://exchange.xforce.ibmcloud.com/vulnerabilities/120209 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-1099
https://notcve.org/view.php?id=CVE-2017-1099
IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659. Jazz Foundation de IBM, podría exponer información potencialmente confidencial a los usuarios autenticados por medio de condiciones de error de rastreo de pila. ID de IBM X-Force: 120659. • http://www.ibm.com/support/docview.wss?uid=swg22004534 https://exchange.xforce.ibmcloud.com/vulnerabilities/120659 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-9698
https://notcve.org/view.php?id=CVE-2016-9698
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999960. Rhapsody DM versiones 4.0, 5.0 y 6.0 de IBM, es vulnerable a una denegación de servicio, causada por un error de inyección XML External Entity (XXE) al procesar datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información altamente confidencial o consumir todos los recursos de memoria disponibles. • http://www.ibm.com/support/docview.wss?uid=swg21999960 http://www.ibm.com/support/docview.wss?uid=swg22002258 http://www.securityfocus.com/bid/96829 https://exchange.xforce.ibmcloud.com/vulnerabilities/119522 • CWE-611: Improper Restriction of XML External Entity Reference •