
CVE-2013-0466
https://notcve.org/view.php?id=CVE-2013-0466
20 Feb 2013 — Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is not properly handled during construction of an error message. Cross-site scripting (XSS) en WebSphere Message Broker IBM v7,0 antes de v7.0.0.6 y v8,0 antes de v8.0.0.2 antes, cuando el soporte wsdl está habilitada en un nodo SOAPInput, permite a atacantes... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC89383 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-3317
https://notcve.org/view.php?id=CVE-2012-3317
05 Dec 2012 — IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300. IBM WebSphere Message Broker v6.1 anterior a v6.1.0.11, v7.0 anterior a v7.0.0.5, y v8.0 anterior a v8.0.0.2 tiene la propiedad incorrecta de cierto programa de desinstalación de Java Runtime Environment (JRE), lo que podría permitir a usuar... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC85477 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2009-0503
https://notcve.org/view.php?id=CVE-2009-0503
13 Feb 2009 — IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs. IBM WebSphere Message Broker v6.1.x anteriores a v6.1.0.2 escribe la contraseña de conexión a la base de datos en el registro de eventos y en el registro del sistema cuando maneja una excepción por un error JDBC, permitiendo a usuarios locales obtener información sens... • http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27011431 • CWE-255: Credentials Management Errors •