
CVE-2014-0970
https://notcve.org/view.php?id=CVE-2014-0970
19 Jul 2014 — The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links via unspecified vectors. El componente GDS en IBM InfoSphere Master Data Management - Collaborative Edition 10.x y 11.x anterior a 11.0 FP4 y InfoSphere Master Data Management Server para Product Information Management 9.0 y 9.1 permite a usuarios remotos a... • http://www-01.ibm.com/support/docview.wss?uid=swg21677304 • CWE-20: Improper Input Validation •

CVE-2013-4057
https://notcve.org/view.php?id=CVE-2013-4057
16 Mar 2014 — Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users. Vulnerabilidad de CSRF en el pack de XML en el servidor de IBM InfoSphere Information 8.5.x hasta 8.5 FP3, 8.7.x hasta 8.7 FP2 y 9.1.x hasta 9.1.2.0 permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR48815 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2013-4058
https://notcve.org/view.php?id=CVE-2013-4058
16 Mar 2014 — Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote authenticated users to execute arbitrary SQL commands via unspecified interfaces. Múltiples vulnerabilidades de inyección SQL en el servidor de IBM InfoSphere Information 8.x hasta 8.5 FP3, 8.7.x hasta 8.7 FP2 y 9.1.x hasta 9.1.2.0 permiten a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de interfaces no especificadas. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR48815 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2013-4059
https://notcve.org/view.php?id=CVE-2013-4059
16 Mar 2014 — Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified interfaces. Múltiples vulnerabilidades de XSS en el servidor de IBM InfoSphere Information 8.x hasta 8.5 FP3, 8.7.x hasta 8.7 FP2 y 9.1.x hasta 9.1.2.0 permiten a atacantes remotos inyectar script Web o HTML arbitrarios a través de interfaces no especificadas. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR48815 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-5427
https://notcve.org/view.php?id=CVE-2013-5427
04 Feb 2014 — Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users. Vulnerabilidad de CSRF en IBM InfoSphere Master Data Management - Collaborative Edition 10.x anteriores a 10.1 FP8 hasta 11.0 e InfoSphere Master Data Management Server para Product Information Manage... • http://www.ibm.com/support/docview.wss?uid=swg21663181 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2013-5426
https://notcve.org/view.php?id=CVE-2013-5426
19 Dec 2013 — Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors. Vulnerabilidad de fijación de sesión en IBM InfoSphere Master Data Management - Collaborative Edition 10.x anteriores a 10.1 IF5 y 11.0 anteriores a IF1 e InfoSphere Master Data Management Serv... • http://www-01.ibm.com/support/docview.wss?uid=swg21660082 • CWE-287: Improper Authentication •

CVE-2013-5440
https://notcve.org/view.php?id=CVE-2013-5440
18 Dec 2013 — IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 allows local users to obtain sensitive information in opportunistic circumstances by leveraging the presence of file content after a failed installation. IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7 y 9.1 permite a usuarios locales obtener información sensible en circunstancias oportunistas aprovechando la presencia de archivos despues de una instalación fallida. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR48095 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2013-4036
https://notcve.org/view.php?id=CVE-2013-4036
27 Nov 2013 — Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en IBM InfoSphere Master Data Management Server para Product Information Management 9.x anterior a la versión 9.1 FP13, e IBM InfoSphere Ma... • http://www-01.ibm.com/support/docview.wss?uid=swg21656857 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-4056
https://notcve.org/view.php?id=CVE-2013-4056
13 Oct 2013 — Cross-site request forgery (CSRF) vulnerability in the Data Quality Console and Information Analyzer components in IBM InfoSphere Information Server 8.7 through FP2 and 9.1 through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users. Vulnerabilidad de CSRF en componentes Data Quality Console e Information Analyzer de IBM InfoSphere Information Server 8.7 hasta FP2 y 9.1 hasta la versión 9.1.2.0 permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios. • http://www-01.ibm.com/support/docview.wss?uid=swg21652413 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2013-4066
https://notcve.org/view.php?id=CVE-2013-4066
02 Oct 2013 — IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to conduct clickjacking attacks by creating an overlay interface on top of the Web Console interface. IBM InfoSphere Information Server v8.0, v8.1, v8.5 hasta FP3, v8.7, y v9.1 permite a atacantes remotos llevar a cabo ataques de phising mediante la creación de un interfaz superpuesto en el interfaz de la consola web. • http://www.ibm.com/support/docview.wss?uid=swg21651343 • CWE-20: Improper Input Validation •