
CVE-2017-1300
https://notcve.org/view.php?id=CVE-2017-1300
01 Nov 2017 — IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 125162. La plataforma OpenPages GRC de IBM, en sus versiones 7.1, 7.2 y 7.3 es vulnerable a ataques de tipo Cross-Site Request Forgery (CSRF). Esto podría permitir que un atacante ejecute acciones maliciosas y no autorizadas transmitidas desde un usuario en el que la web confía. IB... • http://www.ibm.com/support/docview.wss?uid=swg22009684 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2017-1290
https://notcve.org/view.php?id=CVE-2017-1290
01 Nov 2017 — IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125151. La plataforma OpenPages GRC de IBM 7.1, 7.2 y 7.3 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que al... • http://www.ibm.com/support/docview.wss?uid=swg22009770 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-3049
https://notcve.org/view.php?id=CVE-2016-3049
24 Oct 2017 — IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 114712. IBM OpenPages GRC Platform 7.1, 7.2 y 7.3 es vulnerable a inyección HTML. Un atacante remoto podría inyectar código HTML malicioso que, una vez que se visualice, se ejecutaría en el navegador web de la víctima en el contexto de seguridad del si... • http://www.ibm.com/support/docview.wss?uid=swg21997686 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-5049
https://notcve.org/view.php?id=CVE-2015-5049
01 Jan 2016 — SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en la API en IBM OpenPages GRC Platform 7.0 en versiones anteriores a 7.0.0.4 IF3 y 7.1 en versiones anteriores a 7.1.0.1 IF6 permite a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21970590 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2015-0143
https://notcve.org/view.php?id=CVE-2015-0143
03 Oct 2015 — IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to obtain sensitive information by reading error messages. IBM OpenPages GRC Platform 6.2 en versiones anteriores a IF7, 6.2.1 en versiones anteriores a 6.2.1.1 IF5, 7.0 en versiones anteriores a FP4, y 7.1 en versiones anteriores a FP1, permite a usuarios remotos autenticados obtener información sensible mediante la lectura de mensajes de error. • http://www-01.ibm.com/support/docview.wss?uid=swg21963358 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-0145
https://notcve.org/view.php?id=CVE-2015-0145
03 Oct 2015 — Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de CSRF en IBM OpenPages GRC Platform 6.2 en versiones anteriores a IF7, 6.2.1 en versiones anteriores a 6.2.1.1 IF5, 7.0 en versiones anteriores a FP4 y 7.1 en versiones anteriores a FP1 permite a usuarios remotos auten... • http://www-01.ibm.com/support/docview.wss?uid=swg21963358 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2014-8916
https://notcve.org/view.php?id=CVE-2014-8916
03 Oct 2015 — Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0144. Vulnerabilidad de XSS en IBM OpenPages GRC Platform 6.2 en versiones anteriores a IF7, 6.2.1 en versiones anteriores a 6.2.1.1 IF5, 7.0 en versiones anteriores a FP4, y 7.1 en versiones anteriores a FP1 permite a usuarios remo... • http://www-01.ibm.com/support/docview.wss?uid=swg21963358 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-0141
https://notcve.org/view.php?id=CVE-2015-0141
03 Oct 2015 — IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to modify arbitrary user filters via a JSON request. IBM OpenPages GRC Platform 6.2 en versiones anteriores a IF7, 6.2.1 en versiones anteriores a 6.2.1.1 IF5, 7.0 en versiones anteriores a FP4, y 7.1 en versiones anteriores a FP1 permite a usuarios remotos autenticados modificar filtros de usuario arbitrarios a través de una petición JSON. • http://www-01.ibm.com/support/docview.wss?uid=swg21963358 • CWE-284: Improper Access Control •

CVE-2015-0142
https://notcve.org/view.php?id=CVE-2015-0142
03 Oct 2015 — IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to cause a denial of service (maintenance-mode transition and data-storage outage) by calling the System Administration Mode function. IBM OpenPages GRC Platform 6.2 en versiones anteriores a IF7, 6.2.1 en versiones anteriores a 6.2.1.1 IF5, 7.0 en versiones anteriores a FP4, y 7.1 en versiones anteriores a FP1 permite a usuarios remotos autenticados causar una denegación... • http://www-01.ibm.com/support/docview.wss?uid=swg21963358 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-0144
https://notcve.org/view.php?id=CVE-2015-0144
03 Oct 2015 — Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8916. Vulnerabilidad de XSS en IBM OpenPages GRC Platform 6.2 en versiones anteriores a IF7, 6.2.1 en versiones anteriores a 6.2.1.1 IF5, 7.0 en versiones anteriores a FP4, y 7.1 en versiones anteriores a FP1 permite a usuarios remo... • http://www-01.ibm.com/support/docview.wss?uid=swg21963358 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •