
CVE-2014-6112
https://notcve.org/view.php?id=CVE-2014-6112
20 Apr 2018 — IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote attackers to obtain sensitive information by leveraging support for weak SSL ciphers. IBM X-Force ID: 96184. IBM Tivoli Identity Manager, en versiones 5.1.x anteriores a la 5.1.0.15-ISS-TIM-IF0057, y Security Identity Manager, en versiones 6.0.x anteriores a la 6.0.0.4-ISS-SIM-IF0001 y versiones 7.0.x anteriores a... • http://www-01.ibm.com/support/docview.wss?uid=swg21698020 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1483
https://notcve.org/view.php?id=CVE-2017-1483
27 Sep 2017 — IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621. IBM Security Identity Manager Adapters 6.0 y 7.0 no realizan chequeos de autenticación para un recurso o funcionalidad críticos, permitiendo que los usuarios anónimos accedan a áreas protegidas. IBM X-Force ID: 128621. • http://www.ibm.com/support/docview.wss?uid=swg22007375 • CWE-306: Missing Authentication for Critical Function •

CVE-2017-1407
https://notcve.org/view.php?id=CVE-2017-1407
27 Sep 2017 — IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394. IBM Security Identity Manager Virtual Appliance en sus versiones 6.0 y 7.0 podría permitir que un atacante remoto autenticado ejecute comandos arbitrarios en el sistema. Mediante el envío de una petición espec... • http://www.ibm.com/support/docview.wss?uid=swg22007377 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2017-1362
https://notcve.org/view.php?id=CVE-2017-1362
25 Sep 2017 — IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801. IBM Security Identity Manager Adapters 6.0 y 7.0 almacena las credenciales de usuario en texto plano, por lo que podrían ser leídos por un usuario local. IBM X-Force ID: 126801. • http://www.ibm.com/support/docview.wss?uid=swg22007381 • CWE-522: Insufficiently Protected Credentials •

CVE-2014-6106
https://notcve.org/view.php?id=CVE-2014-6106
18 Sep 2017 — Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors. Existe una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en las versiones 5.1, 6.0 y 7.0 de IBM Security Identity Manager que permite que atacantes remotos secuestren la autenticación de usuarios para peticiones... • http://www.securityfocus.com/bid/73167 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2014-6095
https://notcve.org/view.php?id=CVE-2014-6095
18 Nov 2014 — Directory traversal vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to read arbitrary files via unspecified vectors. Una vulnerabilidad de salto de directorio en IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF14 permite a atacantes remotos leer archivos arbitrarios a través de vectores no especificados. • http://secunia.com/advisories/62363 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2014-6096
https://notcve.org/view.php?id=CVE-2014-6096
18 Nov 2014 — Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. Una vulnerabilidad de XSS en IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF4 permite a atacantes remotos inyectar secuencias de comkandos web o HTML arbitrarios a través de una URL manipulada. • http://secunia.com/advisories/62363 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-6098
https://notcve.org/view.php?id=CVE-2014-6098
18 Nov 2014 — IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a crafted request. IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF14 permite a atacantes remotos descubrir credenciales en texto claro a través de una petición manipulada. • http://secunia.com/advisories/62363 • CWE-255: Credentials Management Errors •

CVE-2014-6105
https://notcve.org/view.php?id=CVE-2014-6105
18 Nov 2014 — IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspecified vectors. IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF14 permite a atacantes remotos llevar a cabo ataques de clickjacking a través de vectores no especificados. • http://secunia.com/advisories/62363 • CWE-20: Improper Input Validation •

CVE-2014-6107
https://notcve.org/view.php?id=CVE-2014-6107
18 Nov 2014 — IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session. IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF14 permite a atacantes remotos obtener información sensible de cookies capturando el tráfico de red durante una sesión HTTP. • http://secunia.com/advisories/62363 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •