Page 3 of 39 results (0.004 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

21 Feb 2019 — IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153427. IBM Security Identity Governance and Intelligence, desde la versión 5.2 hasta la 5.2.4.1 Virtual Appliance, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabil... • https://exchange.xforce.ibmcloud.com/vulnerabilities/153427 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

21 Feb 2019 — IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 153428. IBM Security Identity Governance and Intelligence, desde la versió... • https://exchange.xforce.ibmcloud.com/vulnerabilities/153428 • CWE-384: Session Fixation •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

21 Feb 2019 — IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153429. IBM Security Identity Governance and Intelligence, desde la versión 5.2 hasta la 5.2.4.1 Virtual Appliance, divulga información sensible a usuarios no autorizados. Esta información puede emplearse para ejecutar más ataques en el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/153429 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

21 Feb 2019 — IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance generates an error message that includes sensitive information about its environment, users, or associated data which could be used in further attacks against the system. IBM X-Force ID: 153430. IBM Security Identity Governance and Intelligence, desde la versión 5.2 hasta la 5.2.4.1 Virtual Appliance, genera un mensaje de error que incluye información sensible sobre su entorno, usuarios o datos asociados, todo lo cual se... • https://exchange.xforce.ibmcloud.com/vulnerabilities/153430 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

21 Feb 2019 — IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 153386. IBM Security Identity Governance and Intelligence, en versiones 5.2 hasta la 5.2.4.1 Virtual Appliance, contiene credenciales embebidas, como una contraseña o una clave criptográfica, que emplea pa... • https://exchange.xforce.ibmcloud.com/vulnerabilities/153386 • CWE-798: Use of Hard-coded Credentials •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

21 Feb 2019 — IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 153388. IBM Security Identity Governance and Intelligence, desde la versión 5.2 hasta la 5.2.4.1 Virtual Appliance, soporta que múltiples actores int... • https://exchange.xforce.ibmcloud.com/vulnerabilities/153388 • CWE-326: Inadequate Encryption Strength •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 0

07 Sep 2018 — IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentication in IGI for the survey application. IBM X-Force ID: 148601. IBM Security Identity Governance and Intelligence 5.2.3.2 y 5.2.4 podría permitir que un atacante obtenga información sensible debido a la falta de autenticación en IGI para la aplicación de encuestas. IBM X-Force ID: 148601. • http://www.ibm.com/support/docview.wss?uid=ibm10728883 • CWE-306: Missing Authentication for Critical Function •

CVSS: 7.5EPSS: 27%CPEs: 2EXPL: 2

07 Sep 2018 — IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM X-Force ID: 148599. IBM Security Identity Governance and Intelligence 5.2.3.2 y 5.2.4 es vulnerable a una inyección SQL. Un atacante remoto podría enviar instrucciones SQL especialmente manipuladas que podrían permitir que el atacante viese información en la base de ... • https://packetstorm.news/files/id/149315 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

06 Aug 2018 — IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 127399. IBM Security Identity Governance Virtual Appliance, desde la versión 5.2 hasta la 5.2.3.2, no requiere que los usuarios tengan contraseñas fuertes por defecto, lo que facilita que los atacantes comprometan las cuentas de usuario. IBM X-Force ID: 127399. • http://www.ibm.com/support/docview.wss?uid=swg22016869 • CWE-522: Insufficiently Protected Credentials •

CVSS: 4.3EPSS: 0%CPEs: 7EXPL: 0

06 Aug 2018 — IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 127400. IBM Security Guardium Big Data Intelligence (SonarG) desde la versión 5.2 hasta la 5.2.3.2 genera un mensaje de error que incluye información sensible sobre su entorno, usuarios o datos asociados. IBM X-Force ID: 127400. • http://www.ibm.com/support/docview.wss?uid=swg22016869 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •