Page 30 of 178 results (0.014 seconds)

CVSS: 6.3EPSS: 0%CPEs: 5EXPL: 0

The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter. El componente GDS en IBM InfoSphere Master Data Management - Collaborative Edition 10.x y 11.x anterior a 11.0 FP4 y InfoSphere Master Data Management Server para Product Information Management 9.0 y 9.1 permite a usuarios remotos autenticados leer ficheros arbitrarios a través de un parámetro manipulado del fichero UNIX • http://www-01.ibm.com/support/docview.wss?uid=swg21677299 http://www.securityfocus.com/bid/69027 https://exchange.xforce.ibmcloud.com/vulnerabilities/93600 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.8EPSS: 0%CPEs: 13EXPL: 0

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Information Server Metadata Workbench 8.1 through 9.1 allows remote attackers to hijack the authentication of arbitrary users. Vulnerabilidad de CSRF en IBM InfoSphere Information Server Metadata Workbench 8.1 hasta 9.1 permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR49605 http://www-01.ibm.com/support/docview.wss?uid=swg21671141 https://exchange.xforce.ibmcloud.com/vulnerabilities/92273 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 4.3EPSS: 0%CPEs: 10EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified interfaces. Múltiples vulnerabilidades de XSS en el servidor de IBM InfoSphere Information 8.x hasta 8.5 FP3, 8.7.x hasta 8.7 FP2 y 9.1.x hasta 9.1.2.0 permiten a atacantes remotos inyectar script Web o HTML arbitrarios a través de interfaces no especificadas. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR48815 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49200 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49206 http://www-01.ibm.com/support/docview.wss?uid=swg21666684 http://www.securityfocus.com/bid/66151 https://exchange.xforce.ibmcloud.com/vulnerabilities/86548 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 10EXPL: 0

Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote authenticated users to execute arbitrary SQL commands via unspecified interfaces. Múltiples vulnerabilidades de inyección SQL en el servidor de IBM InfoSphere Information 8.x hasta 8.5 FP3, 8.7.x hasta 8.7 FP2 y 9.1.x hasta 9.1.2.0 permiten a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de interfaces no especificadas. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR48815 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49200 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49206 http://www-01.ibm.com/support/docview.wss?uid=swg21666684 http://www.securityfocus.com/bid/66155 https://exchange.xforce.ibmcloud.com/vulnerabilities/86547 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.8EPSS: 0%CPEs: 10EXPL: 0

Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users. Vulnerabilidad de CSRF en el pack de XML en el servidor de IBM InfoSphere Information 8.5.x hasta 8.5 FP3, 8.7.x hasta 8.7 FP2 y 9.1.x hasta 9.1.2.0 permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR48815 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49200 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49206 http://www-01.ibm.com/support/docview.wss?uid=swg21666684 http://www.securityfocus.com/bid/66154 https://exchange.xforce.ibmcloud.com/vulnerabilities/86546 • CWE-352: Cross-Site Request Forgery (CSRF) •