
CVE-2016-0324
https://notcve.org/view.php?id=CVE-2016-0324
12 Jan 2018 — IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges via unspecified vectors. IBM X-Force ID: 111640. IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 hasta la versión 7.0.1.0 anterior a 7.0.1-ISS-SIM-FP0001 permite que usuarios autenticados remotos ejecuten código arbitrario con privilegios de administrador mediante vectores sin especificar. IBM X-For... • http://www-01.ibm.com/support/docview.wss?uid=swg21981438 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2016-0327
https://notcve.org/view.php?id=CVE-2016-0327
12 Jan 2018 — IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors. IBM X-Force ID: 111643. IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 hasta la versión 7.0.1.0 anterior a 7.0.1-ISS-SIM-FP0001 permite que usuarios autenticados remotos ejecuten código arbitrario con privilegios de administrador mediante vectores sin especificar. IBM X-Force ID: 111643. • http://www-01.ibm.com/support/docview.wss?uid=swg21981438 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-0332
https://notcve.org/view.php?id=CVE-2016-0332
12 Jan 2018 — IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. IBM X-Force ID: 111695. IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 hasta la versión 7.0.1.0 anterior a 7.0.1-ISS-SIM-FP0001 no restringe correctamente intentos fallidos de inicio de sesión, lo que facilita que atacantes remotos obtengan acceso media... • http://www-01.ibm.com/support/docview.wss?uid=swg21981438 • CWE-254: 7PK - Security Features •

CVE-2016-0335
https://notcve.org/view.php?id=CVE-2016-0335
12 Jan 2018 — Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. IBM X-Force ID: 111736. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 hasta la versión 7.0.1.0 anterior a 7.0.1-ISS-SIM-FP0001 permite que atacantes remotos ... • http://www-01.ibm.com/support/docview.wss?uid=swg21981438 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2016-0336
https://notcve.org/view.php?id=CVE-2016-0336
12 Jan 2018 — Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111737. Vulnerabilidad de Cross-Site Scripting (XSS) en IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 hasta la versión 7.0.1.0 anterior a 7.0.1-ISS-SIM-FP0001 permite que usuarios autenticados remotos inyecten scripts web o HTML a... • http://www-01.ibm.com/support/docview.wss?uid=swg21981438 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1483
https://notcve.org/view.php?id=CVE-2017-1483
27 Sep 2017 — IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621. IBM Security Identity Manager Adapters 6.0 y 7.0 no realizan chequeos de autenticación para un recurso o funcionalidad críticos, permitiendo que los usuarios anónimos accedan a áreas protegidas. IBM X-Force ID: 128621. • http://www.ibm.com/support/docview.wss?uid=swg22007375 • CWE-306: Missing Authentication for Critical Function •

CVE-2017-1407
https://notcve.org/view.php?id=CVE-2017-1407
27 Sep 2017 — IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394. IBM Security Identity Manager Virtual Appliance en sus versiones 6.0 y 7.0 podría permitir que un atacante remoto autenticado ejecute comandos arbitrarios en el sistema. Mediante el envío de una petición espec... • http://www.ibm.com/support/docview.wss?uid=swg22007377 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2014-6106
https://notcve.org/view.php?id=CVE-2014-6106
18 Sep 2017 — Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors. Existe una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en las versiones 5.1, 6.0 y 7.0 de IBM Security Identity Manager que permite que atacantes remotos secuestren la autenticación de usuarios para peticiones... • http://www.securityfocus.com/bid/73167 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2016-9703
https://notcve.org/view.php?id=CVE-2016-9703
01 Feb 2017 — IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information. IBM Security Identity Manager Virtual Appliance no invalida los tokens de sesión que podrían permitir que un usuario no autorizado con acceso físico a la estación de trabajo obtenga información sensible. • http://www.ibm.com/support/docview.wss?uid=swg21996761 • CWE-384: Session Fixation •

CVE-2016-9704
https://notcve.org/view.php?id=CVE-2016-9704
01 Feb 2017 — IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Security Identity Manager Virtual Appliance es vulnerable a las secuencias de comandos de sitios cruzados. Esta vulnerabilidad permite a usuarios incrustar código JavaScript arbitrario en la IU Web alterando así la funcionalida... • http://www.ibm.com/support/docview.wss?uid=swg21996761 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •