CVE-2014-6106
https://notcve.org/view.php?id=CVE-2014-6106
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors. Existe una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en las versiones 5.1, 6.0 y 7.0 de IBM Security Identity Manager que permite que atacantes remotos secuestren la autenticación de usuarios para peticiones que pueden causar ataques de tipo Cross-Site Scripting (XSS), de envenenamiento de caché web u otros impactos no especificados mediante vectores desconocidos. • http://www.securityfocus.com/bid/73167 https://exchange.xforce.ibmcloud.com/vulnerabilities/96145 https://www-01.ibm.com/support/docview.wss?uid=swg21698020 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2014-6105
https://notcve.org/view.php?id=CVE-2014-6105
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspecified vectors. IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF14 permite a atacantes remotos llevar a cabo ataques de clickjacking a través de vectores no especificados. • http://secunia.com/advisories/62363 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66496 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66624 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66635 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66637 http://www-01.ibm.com/support/docview.wss? • CWE-20: Improper Input Validation •
CVE-2014-6098
https://notcve.org/view.php?id=CVE-2014-6098
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a crafted request. IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF14 permite a atacantes remotos descubrir credenciales en texto claro a través de una petición manipulada. • http://secunia.com/advisories/62363 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66496 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66624 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66635 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66637 http://www-01.ibm.com/support/docview.wss? • CWE-255: Credentials Management Errors •
CVE-2014-6110
https://notcve.org/view.php?id=CVE-2014-6110
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation. IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF14 no realiza debidamente las acciones de cierre de sesión, lo que permite a atacantes remotos acceder a sesiones mediante el aprovechamiento de una estación de trabajo desatendida. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV66496 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66624 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66635 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66637 http://www-01.ibm.com/support/docview.wss? • CWE-284: Improper Access Control •
CVE-2014-6096
https://notcve.org/view.php?id=CVE-2014-6096
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. Una vulnerabilidad de XSS en IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF4 permite a atacantes remotos inyectar secuencias de comkandos web o HTML arbitrarios a través de una URL manipulada. • http://secunia.com/advisories/62363 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66496 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66624 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66635 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66637 http://www-01.ibm.com/support/docview.wss? • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •