CVE-2017-1711
https://notcve.org/view.php?id=CVE-2017-1711
IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532. Las versiones 8.5 y 9.0 de IBM iNotes SUService pueden manipularse para que ejecuten código malicioso de un DLL disfrazado de DLL de windows en el directorio temp. IBM X-Force ID: 134532. • http://www.ibm.com/support/docview.wss?uid=swg22010774 http://www.ibm.com/support/docview.wss?uid=swg22010775 https://exchange.xforce.ibmcloud.com/vulnerabilities/134532 • CWE-426: Untrusted Search Path •
CVE-2017-1720
https://notcve.org/view.php?id=CVE-2017-1720
IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807. Las versiones 8.5 y 9.0 de IBM Notes podrían permitir que un atacante local ejecute comandos arbitrarios manipulando cuidadosamente una línea de comandos enviada mediante el IPC de la memoria compartida. IBM X-Force ID: 134807. • http://www.ibm.com/support/docview.wss?uid=swg22010766 http://www.ibm.com/support/docview.wss?uid=swg22010767 https://exchange.xforce.ibmcloud.com/vulnerabilities/134807 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •