CVE-2018-1943
https://notcve.org/view.php?id=CVE-2018-1943
IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 153385. IBM Cloud Private versiones 3.1.0 y 3.1.1 es vulnerable a la inyección de HTTP HOST Header, generada por una comprobación inadecuada de la entrada. Mediante la persuasión a una víctima a que visite una página web especialmente creada, un atacante remoto podría realizar una explotación a esta vulnerabilidad para inyectar encabezados HTTP arbitrarios, lo que permitirá al atacante conducir varios ataques contra el sistema vulnerable, incluyendo cross-site scripting, envenenamiento por caché o secuestro de sesión. • http://www.securityfocus.com/bid/107828 https://exchange.xforce.ibmcloud.com/vulnerabilities/153385 https://www.ibm.com/support/docview.wss?uid=ibm10871656 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2018-1939
https://notcve.org/view.php?id=CVE-2018-1939
IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 153319. IBM Cloud Private, en su versión 3.1.1, podría permitir que un atacante remoto lleve a cabo ataques de phishing empleando un ataque de redirección abierta. • http://www.securityfocus.com/bid/107302 https://exchange.xforce.ibmcloud.com/vulnerabilities/153319 https://www.ibm.com/support/docview.wss?uid=ibm10871652 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2018-1937
https://notcve.org/view.php?id=CVE-2018-1937
IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153317. IBM Cloud Private, en su versión 3.1.1, podría permitir a un usuario local con privilegios del administrador interceptar datos sensibles sin cifrar. IBM X-Force ID: 153317. • http://www.securityfocus.com/bid/107300 https://exchange.xforce.ibmcloud.com/vulnerabilities/153317 https://www.ibm.com/support/docview.wss?uid=ibm10871766 • CWE-311: Missing Encryption of Sensitive Data •
CVE-2018-1938
https://notcve.org/view.php?id=CVE-2018-1938
IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153318. IBM Cloud Private, en su versión 3.1.1, podría permitir a un usuario local con privilegios del administrador interceptar datos sensibles sin cifrar. IBM X-Force ID: 153318. • http://www.securityfocus.com/bid/107299 https://exchange.xforce.ibmcloud.com/vulnerabilities/153318 https://www.ibm.com/support/docview.wss?uid=ibm10871770 • CWE-311: Missing Encryption of Sensitive Data •
CVE-2018-1843
https://notcve.org/view.php?id=CVE-2018-1843
The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to exchange information only when accessed internally from within the cluster. It could be possible for an attacker with access to network traffic to sniff packets from the connection and uncover data. IBM X-Force ID: 150903 Los servicios IAM (Identity and Access Management) como IBM Cloud Private 3.1.0 no emplean un canal seguro, como SSL, para intercambiar información solo cuando se accede de forma interna desde dentro del clúster. Podría ser posible para un atacante con acceso al tráfico de red rastrear paquetes desde la conexión y descubrir datos. IBM X-Force ID: 150903 • http://www.ibm.com/support/docview.wss?uid=ibm10739845 https://exchange.xforce.ibmcloud.com/vulnerabilities/150903 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •