CVE-2023-50948 – IBM Storage Fusion HCI information disclosure
https://notcve.org/view.php?id=CVE-2023-50948
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 275671. IBM Storage Fusion HCI 2.1.0 a 2.6.1 contiene credenciales codificadas, como una contraseña o clave criptográfica, que utiliza para su propia autenticación entrante, comunicación saliente con componentes externos o cifrado de datos internos. ID de IBM X-Force: 275671. • https://exchange.xforce.ibmcloud.com/vulnerabilities/275671 https://www.ibm.com/support/pages/node/7105509 • CWE-259: Use of Hard-coded Password CWE-798: Use of Hard-coded Credentials •
CVE-2023-47145 – IBM Db2 for Windows privilege escalation
https://notcve.org/view.php?id=CVE-2023-47145
IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402. IBM Db2 para Windows (incluye Db2 Connect Server) 10.5, 11.1 y 11.5 podría permitir a un usuario local escalar sus privilegios al usuario de SYSTEM mediante la funcionalidad de reparación de MSI ID de IBM X-Force: 270402. • https://exchange.xforce.ibmcloud.com/vulnerabilities/270402 https://security.netapp.com/advisory/ntap-20240307-0003 https://www.ibm.com/support/pages/node/7105500 •
CVE-2023-49880 – IBM Financial Transaction Manager for SWIFT Services data manipulation
https://notcve.org/view.php?id=CVE-2023-49880
In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183. En la función Message Entry and Repair (MER) de IBM Financial Transaction Manager para SWIFT Services 3.2.4, se supone que la dirección de envío y el tipo de mensaje de los mensajes FIN son inmutables. Sin embargo, un atacante podría modificar estos elementos de una transacción comercial. • https://exchange.xforce.ibmcloud.com/vulnerabilities/273183 https://www.ibm.com/support/pages/node/7101167 •
CVE-2021-38927 – IBM Aspera Console cross-site scripting
https://notcve.org/view.php?id=CVE-2021-38927
IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 210322. IBM Aspera Console 3.4.0 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría conducir a la divulgación de credenciales dentro de una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/210322 https://www.ibm.com/support/pages/node/7101252 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-43064 – IBM i code execution
https://notcve.org/view.php?id=CVE-2023-43064
Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause arbitrary code to run with the privilege of the user invoking the facsimile support. IBM X-Force ID: 267689. Facsimile Support para IBM i 7.2, 7.3, 7.4 y 7.5 podría permitir que un usuario local obtenga privilegios elevados debido a una llamada de librería no calificada. Un actor malintencionado podría provocar que se ejecutara código arbitrario con el privilegio del usuario que invoca el soporte de fax. • https://exchange.xforce.ibmcloud.com/vulnerabilities/267689 https://www.ibm.com/support/pages/node/7101330 • CWE-427: Uncontrolled Search Path Element •