CVE-2014-3053
https://notcve.org/view.php?id=CVE-2014-3053
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials. Local Management Interface (LMI) en IBM Security Access Manager (ISAM) for Mobile 8.0 con firmware 8.0.0.0 hasta 8.0.0.3 y IBM Security Access Manager for Web 7.0 y 8.0 con firmware 8.0.0.2 y 8.0.0.3, permite a atacantes remotos evadir autenticación a través de una acción de inicio de sesión con credenciales inválidas. • http://secunia.com/advisories/59381 http://secunia.com/advisories/59438 http://www-01.ibm.com/support/docview.wss?uid=swg1IV61557 http://www-01.ibm.com/support/docview.wss?uid=swg21676389 http://www-01.ibm.com/support/docview.wss?uid=swg21676700 http://www.securityfocus.com/bid/68132 https://exchange.xforce.ibmcloud.com/vulnerabilities/93501 • CWE-287: Improper Authentication •
CVE-2014-3073
https://notcve.org/view.php?id=CVE-2014-3073
Unspecified vulnerability in IBM Security Access Manager (ISAM) for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0 allows remote attackers to execute arbitrary code via unknown vectors. Vulnerabilidad no especificada en IBM Security Access Manager (ISAM) for Mobile 8.0 y IBM Security Access Manager for Web 7.0 y 8.0 permite a atacantes remotos ejecutar código arbitrario a través de vectores desconocidos. • http://secunia.com/advisories/59438 http://www-01.ibm.com/support/docview.wss?uid=swg1IV61563 http://www-01.ibm.com/support/docview.wss?uid=swg21676699 http://www.securityfocus.com/bid/68137 https://exchange.xforce.ibmcloud.com/vulnerabilities/93790 •
CVE-2014-0963
https://notcve.org/view.php?id=CVE-2014-0963
The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages. La funcionalidad Reverse Proxy en IBM Global Security Kit (también conocido como GSKit) en IBM Security Access Manager (ISAM) para Web 7.0 anterior a 7.0.0-ISS-SAM-IF0006 y 8.0 anterior a 8.0.0.3-ISS-WGA-IF0002 permite a atacantes remotos causar una denegación de servicio (bucle infinito) a través de mensajes SSL manipulados. • http://secunia.com/advisories/58845 http://secunia.com/advisories/59245 http://secunia.com/advisories/59249 http://www-01.ibm.com/support/docview.wss?uid=swg1IV59660 http://www-01.ibm.com/support/docview.wss?uid=swg21672192 http://www-01.ibm.com/support/docview.wss?uid=swg21676091 http://www-01.ibm.com/support/docview.wss?uid=swg21676092 http://www-304.ibm.com/support/docview.wss? • CWE-399: Resource Management Errors •
CVE-2013-6329
https://notcve.org/view.php?id=CVE-2013-6329
IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of service via a crafted handshake during resumption of an SSLv2 session. IBM Global Security Kit (aka GSKit), tal como se utiliza en Content Manager OnDemand 8.5 y 9.0 y otros productos, permite a atacantes remotos provocar una denegación de servicio a través de un handshake manipulado durante la reanudación de una sesión de SSLv2. • http://secunia.com/advisories/56058 http://www-01.ibm.com/support/docview.wss?uid=swg21659548 http://www-01.ibm.com/support/docview.wss?uid=swg21659716 http://www-01.ibm.com/support/docview.wss?uid=swg21659837 http://www-01.ibm.com/support/docview.wss?uid=swg21669554 http://www-01.ibm.com/support/docview.wss? • CWE-310: Cryptographic Issues •