Page 2 of 14 results (0.004 seconds)

CVSS: 8.6EPSS: 0%CPEs: 7EXPL: 0

27 Sep 2017 — IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621. IBM Security Identity Manager Adapters 6.0 y 7.0 no realizan chequeos de autenticación para un recurso o funcionalidad críticos, permitiendo que los usuarios anónimos accedan a áreas protegidas. IBM X-Force ID: 128621. • http://www.ibm.com/support/docview.wss?uid=swg22007375 • CWE-306: Missing Authentication for Critical Function •

CVSS: 9.0EPSS: 3%CPEs: 7EXPL: 0

27 Sep 2017 — IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394. IBM Security Identity Manager Virtual Appliance en sus versiones 6.0 y 7.0 podría permitir que un atacante remoto autenticado ejecute comandos arbitrarios en el sistema. Mediante el envío de una petición espec... • http://www.ibm.com/support/docview.wss?uid=swg22007377 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

25 Sep 2017 — IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801. IBM Security Identity Manager Adapters 6.0 y 7.0 almacena las credenciales de usuario en texto plano, por lo que podrían ser leídos por un usuario local. IBM X-Force ID: 126801. • http://www.ibm.com/support/docview.wss?uid=swg22007381 • CWE-522: Insufficiently Protected Credentials •

CVSS: 8.8EPSS: 0%CPEs: 20EXPL: 0

18 Sep 2017 — Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors. Existe una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en las versiones 5.1, 6.0 y 7.0 de IBM Security Identity Manager que permite que atacantes remotos secuestren la autenticación de usuarios para peticiones... • http://www.securityfocus.com/bid/73167 • CWE-352: Cross-Site Request Forgery (CSRF) •