Page 5 of 189 results (0.008 seconds)

CVSS: 8.1EPSS: 0%CPEs: 4EXPL: 0

18 Nov 2023 — IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM X-Force ID: 263332. IBM InfoSphere Information Server 11.7 podría permitir a un usuario autenticado cambiar los archivos de instalación debido a una configuración incorrecta de permisos de archivos. ID de IBM X-Force: 263332. • https://exchange.xforce.ibmcloud.com/vulnerabilities/263332 • CWE-276: Incorrect Default Permissions •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

28 Aug 2023 — IBM InfoSphere Information Systems 11.7 could expose information about the host system and environment configuration. IBM X-Force ID: 246332. IBM InfoSphere Information Systems v11.7 podría exponer información sobre el sistema host y la configuración del entorno. IBM X-Force ID: 246332. • https://exchange.xforce.ibmcloud.com/vulnerabilities/246332 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 10.0EPSS: 0%CPEs: 2EXPL: 0

28 Aug 2023 — IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 245400. IBM InfoSphere Information Server v11.7 es vulnerable a Cross-Site Request Forgery lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas desde un usuario en el que confía el sitio web. IBM X-Force ID: 245400. • https://exchange.xforce.ibmcloud.com/vulnerabilities/245400 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 10.0EPSS: 0%CPEs: 2EXPL: 0

28 Aug 2023 — IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 244368. IBM InfoSphere Information Server v11.7 es potencialmente vulnerable a la inyección CSV. Un atacante remoto podría ejecutar comandos arbitrarios en el sistema, debido a una validación incorrecta del contenido de los archivos CSV. • https://exchange.xforce.ibmcloud.com/vulnerabilities/244368 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •

CVSS: 6.8EPSS: 0%CPEs: 4EXPL: 0

19 Jul 2023 — IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352. IBM InfoSphere Information Server v11.7 podría permitir a un usuario autenticado obtener información confidencial debido a una configuración de seguridad insegura en "InfoSphere Data Flow Designer". IBM X-Force ID: 259352. • https://exchange.xforce.ibmcloud.com/vulnerabilities/259352 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.3EPSS: 0%CPEs: 4EXPL: 0

16 Jul 2023 — IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in further attacks against the system. IBM X-Force ID: 257695. IBM InfoSphere Information Server v11.7 podría permitir a un atacante remoto obtener información del sistema utilizando una consulta especialmente manipulada que podría ayudar en futuros ataques contra el sistema. ID de IBM X-Force: 257695. • https://exchange.xforce.ibmcloud.com/vulnerabilities/257695 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 10.0EPSS: 2%CPEs: 4EXPL: 0

22 May 2023 — IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285. • https://exchange.xforce.ibmcloud.com/vulnerabilities/255285 • CWE-502: Deserialization of Untrusted Data •

CVSS: 10.0EPSS: 0%CPEs: 4EXPL: 0

19 May 2023 — IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163. • https://exchange.xforce.ibmcloud.com/vulnerabilities/243163 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.2EPSS: 0%CPEs: 4EXPL: 0

19 May 2023 — IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373. • https://exchange.xforce.ibmcloud.com/vulnerabilities/244373 • CWE-312: Cleartext Storage of Sensitive Information •

CVSS: 5.5EPSS: 0%CPEs: 4EXPL: 0

19 May 2023 — IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 251213. • https://https://exchange.xforce.ibmcloud.com/vulnerabilities/251213 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •