
CVE-2017-1521
https://notcve.org/view.php?id=CVE-2017-1521
26 Oct 2017 — IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications (IBM BigFix Platform 9.2 and 9.5) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129831. IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications (IBM BigFix Platform 9.2 y 9.5) es vulnerable a Cross-Sit... • http://www.ibm.com/support/docview.wss?uid=swg22009673 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1227
https://notcve.org/view.php?id=CVE-2017-1227
31 Jul 2017 — IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force ID: 123906. IBM Tivoli Endpoint Manager podría permitir a un usuario no autorizado consumir todos los recursos y bloquear el sistema. ID de IBM X-Force: 123906. • http://www.ibm.com/support/docview.wss?uid=swg22003222 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2017-1203
https://notcve.org/view.php?id=CVE-2017-1203
19 Jul 2017 — IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123678. La plataforma y las aplicaciones de IBM Tivoli Endpoint Manager (para Lifecycle/Power/Patch) son vulnerables a un problema de tipo cross-site-scripting. Esta vulnerabilidad ... • http://www.ibm.com/support/docview.wss?uid=swg22005246 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1218
https://notcve.org/view.php?id=CVE-2017-1218
19 Jul 2017 — IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123858. IBM Tivoli Endpoint Manager es vulnerable a un problema de tipo cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas por un usuario en el que el sitio web confía. ID de IBM X-Force: 123858. • http://www.ibm.com/support/docview.wss?uid=swg22005246 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2017-1219
https://notcve.org/view.php?id=CVE-2017-1219
19 Jul 2017 — IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 123859. IBM Tivoli Endpoint Manager es vulnerable a un ataque de Inyección XML External Entity (XXE) al procesar datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información confidencial o consumir recursos de memoria. • http://www.ibm.com/support/docview.wss?uid=swg22006014 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2017-1223
https://notcve.org/view.php?id=CVE-2017-1223
19 Jul 2017 — IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123902. IBM Tivoli Endpoint Manager podría per... • http://www.ibm.com/support/docview.wss?uid=swg22005246 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2017-1224
https://notcve.org/view.php?id=CVE-2017-1224
19 Jul 2017 — IBM Tivoli Endpoint Manager uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123903. IBM Tivoli Endpoint Manager usa algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. ID de IBM X-Force: 123903. • http://www.ibm.com/support/docview.wss?uid=swg22005246 • CWE-326: Inadequate Encryption Strength •

CVE-2016-0214
https://notcve.org/view.php?id=CVE-2016-0214
08 Feb 2017 — IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a malicious file. The only way that file would be executed would be through a phishing attack to trick an unsuspecting victim to execute the file. IBM Tivoli Endpoint Manager podría permitir a un atacante remoto subir archivos arbitrarios. Un atacante remoto podría explotar esta vulnerabilidad para subir archivos maliciosos. • http://www.ibm.com/support/docview.wss?uid=swg21993203 • CWE-284: Improper Access Control •

CVE-2016-0296
https://notcve.org/view.php?id=CVE-2016-0296
01 Feb 2017 — IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user. IBM Tivoli Endpoint Manager - Mobile Device Managemen (MDM) almacena información potencialmente sensible en archivos de registro que podrían estar disponibles para un usuario local. • http://www.ibm.com/support/docview.wss?uid=swg21993213 • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2016-0297
https://notcve.org/view.php?id=CVE-2016-0297
01 Feb 2017 — IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques. IBM Tivoli Endpoint Manager - Mobile Device Managemen (MDM) podría permitir a un atacante remoto obtener información sensible debido a un HTTP Strict-Transport-Security Header perdido a través de técnicas man-in-the-middle. • http://www.ibm.com/support/docview.wss?uid=swg21993214 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •