
CVE-2013-4067
https://notcve.org/view.php?id=CVE-2013-4067
02 Oct 2013 — IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or conduct phishing attacks to capture credentials, via unspecified vectors. IBM InfoSphere Information Server v8.0, v8.1, v8.5 hasta FP3, v8.7 y v9.1 permite a atacantes remotos secuestrar sesiones y leer valores de cookies, o llevar a acabo ataques de phising para capturar credenciales a través de vectores no especificados. • http://www.ibm.com/support/docview.wss?uid=swg21651343 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-3034
https://notcve.org/view.php?id=CVE-2013-3034
16 Aug 2013 — Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the web console. Vulnerabilidad Cross-site scripting (XSS) en IBM InfoSphere Information Server hasta v8.5 FP3, v8.7 hasta FP2, y v9.1 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML a través de vectores relacionados con la consola web. • http://www-01.ibm.com/support/docview.wss?uid=swg21646136 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-3040
https://notcve.org/view.php?id=CVE-2013-3040
16 Aug 2013 — IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack. IBM InfoSphere Information Server hasta v8.5 FP3, v8.7 hasta FP2, y 9.1 produce mensajes de fallo de inicio de sesión e indica si el nombre de usuario o la contraseña es incorrecta, lo que permite a atacantes remotos para enumerar las cuentas de usuario a través ... • http://www-01.ibm.com/support/docview.wss?uid=swg21646136 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2013-0585
https://notcve.org/view.php?id=CVE-2013-0585
16 Aug 2013 — Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to the (1) web console and (2) repository management user interfaces. Múltiples vulnerabilidades de cross-site scripting (XSS) en IBM InfoSphere Information Server hasta v8.5 FP3, v8.7 hasta FP2, y 9.1 permiten a los usuarios autenticados remotos inyectar secuencias de comandos web o HTML... • http://www-01.ibm.com/support/docview.wss?uid=swg21646136 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-0502
https://notcve.org/view.php?id=CVE-2013-0502
01 Apr 2013 — Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server 8.1, 8.5 through FP3, 8.7 through FP2, and 9.1 allows remote attackers to inject arbitrary web script or HTML via a malformed URL. Vulnerabilidad XSS en IBM InfoSphere Information Server 8.1, 8.5 a la FP3, 8.7 a la FP2, y 9.1, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de una URL mal formada. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR45274 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-5938
https://notcve.org/view.php?id=CVE-2012-5938
20 Mar 2013 — The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for unspecified files, which allows local users to bypass intended access restrictions via standard filesystem operations. El proceso de instalación en IBM InfoSphere Information Server v8.1, v8.5, v8.7 y v9.1 sobre UNIX y Linux, establece permisos y propietarios incorrectamente, lo que permite a usuarios locales evitar las restricciones de acceso establecidas a tr... • http://www.ibm.com/support/docview.wss?uid=swg21628844 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2012-0204
https://notcve.org/view.php?id=CVE-2012-0204
31 Jan 2013 — Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory. Vulnerabilidad de búsqueda de ruta no confiable en el Import Export Manager v8.1 hasta v9.1 en InfoSphere Information Server MetaBrokers & Bridges (MBB) en IBM InfoSphere Information Server v8.1, v... • http://www-01.ibm.com/support/docview.wss?uid=swg21623501 •

CVE-2012-0705
https://notcve.org/view.php?id=CVE-2012-0705
31 Jan 2013 — InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors. InfoSphere Import Export Manager en InfoSphere Information Server MetaBrokers & Bridges (MBB) en IBM InfoSphere Information Server v8.1, v8.5 anterior a FP3, v8.7, y v9.1 no valida datos de entrada no especificados... • http://www-01.ibm.com/support/docview.wss?uid=swg21623501 • CWE-20: Improper Input Validation •