
CVE-2016-0280
https://notcve.org/view.php?id=CVE-2016-0280
08 Aug 2016 — Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and InfoSphere Information Governance Catalog 11.3 before 11.3.1.2, and Information Server Framework and InfoSphere Information Governance Catalog 11.5 before 11.5.0.1 allows remote authenticated users t... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR55452 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-7490
https://notcve.org/view.php?id=CVE-2015-7490
03 Mar 2016 — IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie. IBM InfoSphere Information Server 8.5 hasta la versión FP3, 8.7 hasta la versión FP2, 9.1 hasta la versión 9.1.2.0, 11.3 hasta la versión 11.3.1.2 y 11.5 permite a usuarios remotos autentificados eludir las restricciones destinadas al acceso a través de una cookie modificada. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR54787 • CWE-284: Improper Access Control •

CVE-2015-5021
https://notcve.org/view.php?id=CVE-2015-5021
04 Nov 2015 — IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors. IBM InfoSphere Information Server 11.3 y 11.5 permite a los usuarios remotos autenticados DataStage eludir las restricciones destinadas a ejecución de tarea u obtener información sensible a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR54224 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-1901
https://notcve.org/view.php?id=CVE-2015-1901
28 Jun 2015 — The installer in IBM InfoSphere Information Server 8.5 through 11.3 before 11.3.1.2 allows local users to obtain sensitive information via unspecified commands. El instalador en IBM InfoSphere Information Server 8.5 hasta 11.3 anterior a 11.3.1.2 permite a usuarios locales obtener información sensible a través de comandos no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR52549 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-0180
https://notcve.org/view.php?id=CVE-2015-0180
25 May 2015 — The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modification via unspecified vectors. Connector Migration Tool en IBM InfoSphere Information Server 8.1 hasta 11.3 permite a usuarios remotos autenticados evadir las restricciones sobre la creación y modificación de empleo a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR51665 • CWE-284: Improper Access Control •

CVE-2014-8896
https://notcve.org/view.php?id=CVE-2014-8896
22 Dec 2014 — The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify the administrator's credentials and consequently gain privileges via unspecified vectors. El servidor Collaboration Server en IBM InfoSphere Master Data Management Server for Product Information Management 9.x ha... • http://www-01.ibm.com/support/docview.wss?uid=swg21692176 • CWE-287: Improper Authentication •

CVE-2014-8897
https://notcve.org/view.php?id=CVE-2014-8897
22 Dec 2014 — Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8898 and CVE-2014-8899. Vulnerabilidad de XSS en el Collaboration Server en IBM ... • http://www-01.ibm.com/support/docview.wss?uid=swg21692176 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-8898
https://notcve.org/view.php?id=CVE-2014-8898
22 Dec 2014 — Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8897 and CVE-2014-8899. Vulnerabilidad de XSS en el Collaboration Server en IBM ... • http://www-01.ibm.com/support/docview.wss?uid=swg21692176 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-8899
https://notcve.org/view.php?id=CVE-2014-8899
22 Dec 2014 — Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8897 and CVE-2014-8898. Vulnerabilidad de XSS en el Collaboration Server en IBM ... • http://www-01.ibm.com/support/docview.wss?uid=swg21692176 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-4775
https://notcve.org/view.php?id=CVE-2014-4775
17 Aug 2014 — IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain sensitive information via unspecified vectors. IBM InfoSphere Master Data Management - Collaborative Edition 10.x anterior a 10.1-FP11 y 11.x anterior a 11.0-FP5 y InfoSphere Master Data Manag... • http://www-01.ibm.com/support/docview.wss?uid=swg21681640 • CWE-255: Credentials Management Errors •