Page 2 of 8 results (0.006 seconds)

CVSS: 5.3EPSS: 0%CPEs: 26EXPL: 0

IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696. IBM Tivoli Monitoring V6 podría permitir a un usuario no autenticado acceder a consultas SOAP que podrían contener información confidencial. IBM X-Force ID: 117696. • http://www.ibm.com/support/docview.wss?uid=swg22000909 http://www.securityfocus.com/bid/99259 https://exchange.xforce.ibmcloud.com/vulnerabilities/117696 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.9EPSS: 0%CPEs: 23EXPL: 0

IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223. IBM Tivoli Monitoring 6.2 y 6.3 es vulnerable a posibles ataques de inyección de encabezado de host que podría conducir a envenenamiento de caché HTTP o elusión del firewall. Referencia IBM #: 1997223. • http://www.ibm.com/support/docview.wss?uid=swg21997223 • CWE-254: 7PK - Security Features •

CVSS: 8.5EPSS: 0%CPEs: 33EXPL: 0

IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands. IBM Tivoli Monitoring (ITM) 6.2.0 hasta FP03, 6.2.1 hasta FP04, 6.2.2 hasta FP09, 6.2.3 hasta FP05, y 6.3.0 anterior a FP04 permite a usuarios remotos autenticados evadir las restricciones de acceso y ejecutar comandos arbitrarios mediante el aprovechamiento de la autoridad de visualización 'Take Action' para modificar los comandos en proceso. • http://www-01.ibm.com/support/docview.wss?uid=swg21690932 https://exchange.xforce.ibmcloud.com/vulnerabilities/96911 • CWE-264: Permissions, Privileges, and Access Controls •