
CVE-2014-3063
https://notcve.org/view.php?id=CVE-2014-3063
17 Aug 2014 — IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 allow local users to obtain administrator privileges via unspecified vectors. IBM InfoSphere Master Data Management - Collaborative Edition 10.x anterior a 10.1-FP11 y 11.x anterior a 11.0-FP5 y InfoSphere Master Data Management Server for Product Information Managemen... • http://secunia.com/advisories/60680 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-0966
https://notcve.org/view.php?id=CVE-2014-0966
17 Aug 2014 — SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en el componente GDS en IBM InfoSphere Master Data Management - Collaborative Edition 10.x y 11.x anterior a 11.0-FP5 y InfoSphere... • http://secunia.com/advisories/60679 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2014-0969
https://notcve.org/view.php?id=CVE-2014-0969
17 Aug 2014 — Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to hijack the authentication of arbitrary users. Vulnerabilidad de CSRF en el componente GDS en IBM InfoSphere Master Data Management - Collaborative Edition 10.x y 11.x anterior a 11.0-FP5 y InfoSpher... • http://secunia.com/advisories/60679 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2014-3071
https://notcve.org/view.php?id=CVE-2014-3071
26 Jul 2014 — Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection. Vulnerabilidad de XSS en Data Quality Console en IBM InfoSphere Information Server 11.3 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada para añadir una conexión de proyecto. • http://secunia.com/advisories/59267 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •