Page 3 of 39 results (0.005 seconds)

CVSS: 6.8EPSS: 0%CPEs: 5EXPL: 0

The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993. Sametime WebPlayer 8.5.2 y 9.0 es vulnerable a una inyección de script por la cual un sitio malicioso puede inyectar sus propios scripts mediante la explotación de una vulnerabilidad de la misma forma que funciona WebPlayer. IBM X-Force ID: 113993. • http://www.ibm.com/support/docview.wss?uid=swg22006447 http://www.securityfocus.com/bid/100531 https://exchange.xforce.ibmcloud.com/vulnerabilities/113993 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVSS: 6.5EPSS: 0%CPEs: 5EXPL: 0

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111894. IBM Sametime Enterprise Meeting Server 8.5.2 y 9.0 podría permitir que un usuario autenticado que haya sido invitado a una sala de reuniones de Sametime detenga la compartición de pantalla mediante Cross-Site Request Forgery (CSRF). IBM X-Force ID: 111894. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/111894 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 5.4EPSS: 0%CPEs: 5EXPL: 0

IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113945. IBM Sametime Meeting Server 8.5.2 y 9.0 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, alterando las funcionalidades planeadas. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/113945 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 5EXPL: 0

IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. IBM X-Force ID: 113898. IBM Sametime Media Services 8.5.2 y 9.0 puede divulgar información sensible en registros de errores de seguimiento de pila que podría ayudar a un atacante en futuros ataques. IBM X-Force ID: 113898. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/113898 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855. IBM Sametime Meeting Server v8.5.2 y v9.0 podría almacenar credenciales de un usuario de Sametime Meetings en la memoria caché local de su navegador, pudiendo un usuario local acceder a ellas. IBM X-Force ID: 113855. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/113855 • CWE-255: Credentials Management Errors •