CVE-2014-6098
https://notcve.org/view.php?id=CVE-2014-6098
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a crafted request. IBM Security Identify Manager 6.x anterior a 6.0.0.3 IF14 permite a atacantes remotos descubrir credenciales en texto claro a través de una petición manipulada. • http://secunia.com/advisories/62363 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66496 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66624 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66635 http://www-01.ibm.com/support/docview.wss?uid=swg1IV66637 http://www-01.ibm.com/support/docview.wss? • CWE-255: Credentials Management Errors •
CVE-2014-0961
https://notcve.org/view.php?id=CVE-2014-0961
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de CSRF en IBM Tivoli Identity Manager (ITIM) 5.0 anterior a 5.0.0.15 y 5.1 anterior a 5.1.0.15 y IBM Security Identity Manager (ISIM) 6.0 anterior a 6.0.0.2 permite a usuarios remotos autenticados secuestrar la autenticación de usuarios arbitrarios para solicitudes que insertan secuencias de XSS. • http://secunia.com/advisories/59080 http://www-01.ibm.com/support/docview.wss?uid=swg21674754 http://www.securityfocus.com/bid/67909 https://exchange.xforce.ibmcloud.com/vulnerabilities/92747 • CWE-352: Cross-Site Request Forgery (CSRF) •