CVE-2023-38002 – IBM Storage Scale session fixation
https://notcve.org/view.php?id=CVE-2023-38002
IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or manipulate an active session to gain access to the system. IBM X-Force ID: 260208. IBM Storage Scale 5.1.0.0 a 5.1.9.2 podría permitir que un usuario autenticado robe o manipule una sesión activa para obtener acceso al sistema. ID de IBM X-Force: 260208. • https://exchange.xforce.ibmcloud.com/vulnerabilities/260208 https://www.ibm.com/support/pages/node/7149699 • CWE-384: Session Fixation •
CVE-2024-25026 – IBM WebSphere Application Server denial of service
https://notcve.org/view.php?id=CVE-2024-25026
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 281516. IBM WebSphere Application Server 8.5, 9.0 e IBM WebSphere Application Server Liberty 17.0.0.3 a 24.0.0.4 son vulnerables a una denegación de servicio provocada por el envío de una solicitud especialmente manipulada. Un atacante remoto podría aprovechar esta vulnerabilidad para hacer que el servidor consuma recursos de memoria. • https://exchange.xforce.ibmcloud.com/vulnerabilities/281516 https://www.ibm.com/support/pages/node/7149330 • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2023-47731 – IBM QRadar Suite Software cross-site scripting
https://notcve.org/view.php?id=CVE-2023-47731
IBM QRadar Suite Software 1.10.12.0 through 1.10.19.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 272203. IBM QRadar Suite Software 1.10.12.0 a 1.10.19.0 e IBM Cloud Pak for Security 1.10.0.0 a 1.10.11.0 son vulnerables a cross-site scripting almacenado. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría conducir a la divulgación de credenciales dentro de una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/272203 https://https://www.ibm.com/support/pages/node/7148994 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-40745 – IBM Aspera Faspex information disclosure
https://notcve.org/view.php?id=CVE-2022-40745
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452. IBM Aspera Faspex 5.0.0 a 5.0.7 podría permitir que un usuario local obtenga información confidencial debido a una seguridad más débil de lo esperado. ID de IBM X-Force: 236452. • https://exchange.xforce.ibmcloud.com/vulnerabilities/236452 https://www.ibm.com/support/pages/node/7148632 • CWE-326: Inadequate Encryption Strength •
CVE-2023-37397 – IBM Aspera Faspex data manipulation
https://notcve.org/view.php?id=CVE-2023-37397
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM X-Force ID: 259672. IBM Aspera Faspex 5.0.0 a 5.0.7 podría permitir que un usuario local obtenga o modifique información confidencial debido a un cifrado inadecuado de ciertos datos. ID de IBM X-Force: 259672. • https://exchange.xforce.ibmcloud.com/vulnerabilities/259672 https://www.ibm.com/support/pages/node/7148632 • CWE-326: Inadequate Encryption Strength •