CVE-2014-3064
https://notcve.org/view.php?id=CVE-2014-3064
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter. El componente GDS en IBM InfoSphere Master Data Management - Collaborative Edition 10.x y 11.x anterior a 11.0 FP4 y InfoSphere Master Data Management Server para Product Information Management 9.0 y 9.1 permite a usuarios remotos autenticados leer ficheros arbitrarios a través de un parámetro manipulado del fichero UNIX • http://www-01.ibm.com/support/docview.wss?uid=swg21677299 http://www.securityfocus.com/bid/69027 https://exchange.xforce.ibmcloud.com/vulnerabilities/93600 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-0970
https://notcve.org/view.php?id=CVE-2014-0970
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links via unspecified vectors. El componente GDS en IBM InfoSphere Master Data Management - Collaborative Edition 10.x y 11.x anterior a 11.0 FP4 y InfoSphere Master Data Management Server para Product Information Management 9.0 y 9.1 permite a usuarios remotos autenticados inyectar enlaces a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21677304 https://exchange.xforce.ibmcloud.com/vulnerabilities/92950 • CWE-20: Improper Input Validation •
CVE-2014-0873
https://notcve.org/view.php?id=CVE-2014-0873
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSphere Master Data Management (MDM) Server 8.5 before 8.5.0.82, 9.0.1 before 9.0.1.38, 9.0.2 before 9.0.2.35, 10.0 before 10.0.0.0.26, and 10.1 before 10.1.0.0.15 allow remote attackers to hijack the authentication of arbitrary users. Múltiples vulnerabilidades de CSRF en las interfaces (1) Data Stewardship, (2) Business Admin y (3) Product en el servidor de IBM InfoSphere Master Data Management (MDM) 8.5 anterior a 8.5.0.82, 9.0.1 anterior a 9.0.1.38, 9.0.2 anterior a 9.0.2.35, 10.0 anterior a 10.0.0.0.26 y 10.1 anterior a 10.1.0.0.15 permiten a atacantes remotos secuestrar la autenticación de usuarios arbitrarios. • http://www-01.ibm.com/support/docview.wss?uid=swg21666462 https://exchange.xforce.ibmcloud.com/vulnerabilities/90994 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2013-5427
https://notcve.org/view.php?id=CVE-2013-5427
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users. Vulnerabilidad de CSRF en IBM InfoSphere Master Data Management - Collaborative Edition 10.x anteriores a 10.1 FP8 hasta 11.0 e InfoSphere Master Data Management Server para Product Information Management 9.0 y 9.1 permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios. • http://www.ibm.com/support/docview.wss?uid=swg21663181 https://exchange.xforce.ibmcloud.com/vulnerabilities/87536 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2013-5426
https://notcve.org/view.php?id=CVE-2013-5426
Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors. Vulnerabilidad de fijación de sesión en IBM InfoSphere Master Data Management - Collaborative Edition 10.x anteriores a 10.1 IF5 y 11.0 anteriores a IF1 e InfoSphere Master Data Management Server para Product Information Management 9.x anteriores a 9.1 IF11 permite a usuarios autenticados remotamente secuestrar sesiones web a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21660082 https://exchange.xforce.ibmcloud.com/vulnerabilities/87535 • CWE-287: Improper Authentication •