CVE-2014-6170
https://notcve.org/view.php?id=CVE-2014-6170
The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault. El nodo HTTPInput en IBM WebSphere Message Broker 7.0 anterior a 7.0.0.8 y 8.0 anterior a 8.0.0.6 y IBM Integration Bus 9.0 anterior a 9.0.0.4 permite a atacantes remotos obtener información sensible mediante la provocación de un fallo SOAP. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT01929 http://www-01.ibm.com/support/docview.wss?uid=swg21690725 https://exchange.xforce.ibmcloud.com/vulnerabilities/98309 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-6160
https://notcve.org/view.php?id=CVE-2014-6160
IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation. IBM WebSphere Service Registry y Repository (WSRR) 8.5 anterior a 8.5.0.1, cuando se usan Chrome y WebSEAL, no procesa adecuadamente ServiceRegistryDashboard las acciones de logout, lo que permite a atacantes saltarse las restricciones de acceso aprovechando una estación de trabajo desatendida. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV63498 http://www-01.ibm.com/support/docview.wss?uid=swg21693389 https://exchange.xforce.ibmcloud.com/vulnerabilities/97709 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2014-6186
https://notcve.org/view.php?id=CVE-2014-6186
IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.1 allows remote authenticated users to bypass intended object-access restrictions via the datagraph. IBM WebSphere Service Registry y Repository (WSRR) 6.3.x anterior a 6.3.0.5, 7.0.x a través de 7.0.0.5, 7.5.x anterior a 7.5.0.3, y 8.0.x anterior a 8.0.0.1 permite a usuarios autenticados evadir las restricciones de acceso a objetos a través de datagraph. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV26309 http://www.ibm.com/support/docview.wss?uid=swg21693379 http://www.ibm.com/support/docview.wss?uid=swg21693381 http://www.ibm.com/support/docview.wss?uid=swg21693384 http://www.ibm.com/support/docview.wss? • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2014-6153
https://notcve.org/view.php?id=CVE-2014-6153
The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. La interfaz de usuario web en IBM WebSphere Service Registry y Repository (WSRR) 6.3.x a través de 6.3.0.5, 7.0.x a través de7.0.0.5, 7.5.x a través de7.5.0.4, 8.0.x anterior a 8.0.0.3, y 8.5.x anterior a 8.5.0.1 no establece el indicador de seguridad en una cookie de sesión https, lo cual hace más fácil a atacantes remotos capturar dicha cookie interceptando la transmisión dentro de una sesión http. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV64010 http://www.ibm.com/support/docview.wss?uid=swg21693379 http://www.ibm.com/support/docview.wss?uid=swg21693381 http://www.ibm.com/support/docview.wss?uid=swg21693384 http://www.ibm.com/support/docview.wss? • CWE-310: Cryptographic Issues •
CVE-2014-6180
https://notcve.org/view.php?id=CVE-2014-6180
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the HTTP User-Agent header. Vulnerabilidad XSS en la interfaz de usuario web de IBM WebSphere Service Registry y Repository (WSRR) 7.0.x anterior a 7.0.0.5 y 7.5.x anterior a 7.5.0.1 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de la cabecera HTTP User-Agent. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV01657 http://www.ibm.com/support/docview.wss?uid=swg21693381 http://www.ibm.com/support/docview.wss?uid=swg21693384 https://exchange.xforce.ibmcloud.com/vulnerabilities/98515 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •