CVE-2017-1366
https://notcve.org/view.php?id=CVE-2017-1366
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859. IBM Security Identity Governance Virtual Appliance desde la versión 5.2 hasta la 5.2.3.2 emplea algoritmos criptográficos más débiles de lo esperado que podrían permitir que un atacante descifre información altamente sensible. IBM X-Force ID: 126859. • http://www.ibm.com/support/docview.wss?uid=swg22016869 https://exchange.xforce.ibmcloud.com/vulnerabilities/126859 • CWE-326: Inadequate Encryption Strength •
CVE-2017-1368
https://notcve.org/view.php?id=CVE-2017-1368
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 126861. IBM Security Identity Governance Virtual Appliance, desde la versión 5.2 hasta la 5.2.3.2, no establece el atributo secure en los tokens de autorización o las cookies de sesión. • http://www.ibm.com/support/docview.wss?uid=swg22016869 https://exchange.xforce.ibmcloud.com/vulnerabilities/126861 • CWE-384: Session Fixation •
CVE-2017-1755
https://notcve.org/view.php?id=CVE-2017-1755
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 could allow a local attacker to inject commands into malicious files that could be executed by the administrator. IBM X-Force ID: 135855. IBM Security Identity Governance Virtual Appliance desde la versión 5.2 hasta la 5.2.3.2 podría permitir que un atacante local inyecte comandos en archivos maliciosos que podrían ser ejecutados por el administrador. IBM X-Force ID: 135855. • http://www.ibm.com/support/docview.wss?uid=swg22016869 https://exchange.xforce.ibmcloud.com/vulnerabilities/135855 •
CVE-2017-1396
https://notcve.org/view.php?id=CVE-2017-1396
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 127342. IBM Security Identity Governance Virtual Appliance, desde la versión 5.2 hasta la 5.2.3.2, especifica permisos para un recurso crítico para la seguridad de forma que permite que ese recurso sea leído o modificado por actores no planeados. IBM X-Force ID: 127342. • http://www.ibm.com/support/docview.wss?uid=swg22016869 https://exchange.xforce.ibmcloud.com/vulnerabilities/127342 • CWE-275: Permission Issues •
CVE-2017-1412
https://notcve.org/view.php?id=CVE-2017-1412
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 127400. IBM Security Guardium Big Data Intelligence (SonarG) desde la versión 5.2 hasta la 5.2.3.2 genera un mensaje de error que incluye información sensible sobre su entorno, usuarios o datos asociados. IBM X-Force ID: 127400. • http://www.ibm.com/support/docview.wss?uid=swg22016869 https://exchange.xforce.ibmcloud.com/vulnerabilities/127400 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •