
CVE-2017-1303
https://notcve.org/view.php?id=CVE-2017-1303
31 Jul 2017 — IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125457. IBM WebSphere Portal y Web Content Manager 7.0, 8.0, 8.5 y 9.0 son vulnerables a Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los usuarios que incrusten un código arbitrario ... • http://www.ibm.com/support/docview.wss?uid=swg22004979 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1217
https://notcve.org/view.php?id=CVE-2017-1217
05 Jul 2017 — IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857 IBM WebSphere Portal 8.5 y 9.9 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a usuarios incrustar código Javascript aleatorio en la interfaz web lo que alteraría la funcionalidad planeada y potencialment... • http://www.ibm.com/support/docview.wss?uid=swg22004348 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1156
https://notcve.org/view.php?id=CVE-2017-1156
05 May 2017 — IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force. ID: 122592 WebSphere Portal de IBM versiones... • http://www.ibm.com/support/docview.wss?uid=swg22000153 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2017-1120
https://notcve.org/view.php?id=CVE-2017-1120
27 Mar 2017 — IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000152. IBM WebSphere Portal 8.5 y 9.0 es vulnerable a secuencias de comandos de sitios cruzados. Esta vulnerabilidad permite a usuarios incrustar código JavaScript arbitrario en la IU Web alterando así la funcionalidad potencia... • http://www.ibm.com/support/docview.wss?uid=swg22000152 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-8922
https://notcve.org/view.php?id=CVE-2016-8922
01 Feb 2017 — Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. Exphox WebRadar es vulnerable a las secuencias de comandos de sitios cruzados. Esta vulnerabilidad permite a usuarios incrustar código JavaScript arbitrario en la IU Web alterando así la funcionalidad prevista que potencialmente conduce a la divulgación de creden... • http://www.ibm.com/support/docview.wss?uid=swg21993561 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-5954
https://notcve.org/view.php?id=CVE-2016-5954
12 Sep 2016 — IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before CF12 allows remote authenticated users to cause a denial of service by uploading temporary files. IBM WebSphere Portal 6.1.0 hasta la versión 6.1.0.6 CF27, 6.1.5 hasta la versión 6.1.5.3 CF27, 7.0.0 hasta la versión 7.0.0.2 CF30, 8.0.0 hasta la versión 8.0.0.1 CF21 y 8.5.0 en versiones anteriores a CF12 permite a usuarios remotos autenticados provocar una dene... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI67037 • CWE-284: Improper Access Control •

CVE-2016-2925
https://notcve.org/view.php?id=CVE-2016-2925
08 Aug 2016 — Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en IBM WebSphere Portal 6.1.0.x hasta la versión 6.1.0.6 CF27, 6.1.5.x hasta la versión 6.1.5.3 CF27, 7.x hasta la versión 7.0.0.2 CF30, 8.0.0.x hasta la versión 8.0.0.1 CF21 y 8.5.0 en versiones... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI62749 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-2901
https://notcve.org/view.php?id=CVE-2016-2901
26 Jun 2016 — Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Manager allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de CSRF en la aplicación PA_Theme_Creator en IBM WebSphere Portal 8.5 CF08 hasta la versión CF10 y Web Content Manager permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios para peticiones que inserten sec... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI62594 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2015-7428
https://notcve.org/view.php?id=CVE-2015-7428
29 Feb 2016 — Open redirect vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. Vulnerabilidad de redirección abierta en IBM WebSphere Portal 8.0.x en versiones anteriores a 8.0.0.1 CF20 y 8.5.x en versiones anteriores a 8.5.0.0 CF09 permite a atacantes remotos redirigir a usuarios a sitios web arbitrarios y llevar a cabo ataques de phishing a través de una URL manipul... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI51589 •

CVE-2015-7455
https://notcve.org/view.php?id=CVE-2015-7455
29 Feb 2016 — IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI. IBM WebSphere Portal 7.x hasta la versión 7.0.0.2 CF29, 8.0.x en versiones anteriores a 8.0.0.1 CF20 y 8.5.x en versiones anteriores a 8.5.0.0 CF09 usa permisos débiles para elementos de contenido, lo que permite a usuarios remotos autenticados hacer modificaciones a través de la UI... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI51234 • CWE-264: Permissions, Privileges, and Access Controls •