CVE-2024-22352 – IBM InfoSphere Information Server information disclosure
https://notcve.org/view.php?id=CVE-2024-22352
IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 280361. IBM InfoSphere Information Server 11.7 almacena información potencialmente confidencial en archivos de registro que un usuario local podría leer. ID de IBM X-Force: 280361. • https://exchange.xforce.ibmcloud.com/vulnerabilities/280361 https://www.ibm.com/support/pages/node/7117184 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2023-32331 – IBM Connect:Express for UNIX denial of service
https://notcve.org/view.php?id=CVE-2023-32331
IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979. IBM Connect:Express para UNIX 1.5.0 es vulnerable a un desbordamiento de búfer que podría permitir a un atacante remoto provocar una denegación de servicio a través de la interfaz de usuario de su navegador. ID de IBM X-Force: 254979. • https://exchange.xforce.ibmcloud.com/vulnerabilities/254979 https://www.ibm.com/support/pages/node/7011443 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2023-38360 – IBM CICS TX cross-site scripting
https://notcve.org/view.php?id=CVE-2023-38360
IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260769. IBM CICS TX Advanced 10.1 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría conducir a la divulgación de credenciales dentro de una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/260769 https://www.ibm.com/support/pages/node/7066435 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-38362 – IBM CICS TX information disclosure
https://notcve.org/view.php?id=CVE-2023-38362
IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814. IBM CICS TX Advanced 10.1 podría revelar información confidencial a un atacante remoto debido a una discrepancia observable en las respuestas HTTP. ID de IBM X-Force: 260814. • https://exchange.xforce.ibmcloud.com/vulnerabilities/260814 https://https://www.ibm.com/support/pages/node/7066430 • CWE-204: Observable Response Discrepancy •
CVE-2022-43890 – IBM Security Verify Privilege On-Premises information disclosure
https://notcve.org/view.php?id=CVE-2022-43890
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240453. IBM Security Verify Privilege On-Premises 11.5 podría revelar información confidencial a través de una solicitud HTTP que podría ayudar a un atacante en futuros ataques contra el sistema. ID de IBM X-Force: 240453. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240453 https://www.ibm.com/support/pages/node/7108660 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •