Page 3 of 29 results (0.026 seconds)

CVSS: 6.8EPSS: 0%CPEs: 10EXPL: 0

Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users. Vulnerabilidad de CSRF en el pack de XML en el servidor de IBM InfoSphere Information 8.5.x hasta 8.5 FP3, 8.7.x hasta 8.7 FP2 y 9.1.x hasta 9.1.2.0 permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR48815 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49200 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49206 http://www-01.ibm.com/support/docview.wss?uid=swg21666684 http://www.securityfocus.com/bid/66154 https://exchange.xforce.ibmcloud.com/vulnerabilities/86546 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 2.1EPSS: 0%CPEs: 5EXPL: 0

IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 allows local users to obtain sensitive information in opportunistic circumstances by leveraging the presence of file content after a failed installation. IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7 y 9.1 permite a usuarios locales obtener información sensible en circunstancias oportunistas aprovechando la presencia de archivos despues de una instalación fallida. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR48095 http://www-01.ibm.com/support/docview.wss?uid=swg21659957 https://exchange.xforce.ibmcloud.com/vulnerabilities/87816 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.8EPSS: 0%CPEs: 8EXPL: 0

IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or conduct phishing attacks to capture credentials, via unspecified vectors. IBM InfoSphere Information Server v8.0, v8.1, v8.5 hasta FP3, v8.7 y v9.1 permite a atacantes remotos secuestrar sesiones y leer valores de cookies, o llevar a acabo ataques de phising para capturar credenciales a través de vectores no especificados. • http://www.ibm.com/support/docview.wss?uid=swg21651343 http://www.securityfocus.com/bid/62768 https://exchange.xforce.ibmcloud.com/vulnerabilities/86598 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.3EPSS: 0%CPEs: 8EXPL: 0

IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to conduct clickjacking attacks by creating an overlay interface on top of the Web Console interface. IBM InfoSphere Information Server v8.0, v8.1, v8.5 hasta FP3, v8.7, y v9.1 permite a atacantes remotos llevar a cabo ataques de phising mediante la creación de un interfaz superpuesto en el interfaz de la consola web. • http://www.ibm.com/support/docview.wss?uid=swg21651343 http://www.securityfocus.com/bid/62767 https://exchange.xforce.ibmcloud.com/vulnerabilities/86597 • CWE-20: Improper Input Validation •

CVSS: 5.0EPSS: 0%CPEs: 8EXPL: 0

IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack. IBM InfoSphere Information Server hasta v8.5 FP3, v8.7 hasta FP2, y 9.1 produce mensajes de fallo de inicio de sesión e indica si el nombre de usuario o la contraseña es incorrecta, lo que permite a atacantes remotos para enumerar las cuentas de usuario a través de un ataque de fuerza bruta. • http://www-01.ibm.com/support/docview.wss?uid=swg21646136 http://www.securityfocus.com/bid/61755 https://exchange.xforce.ibmcloud.com/vulnerabilities/84765 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •