CVE-2014-6164
https://notcve.org/view.php?id=CVE-2014-6164
IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL. IBM WebSphere Application Server 8.0.x anterior a 8.0.0.10 y 8.5.x anterior a 8.5.5.4 permite a atacantes remotos falsificar las cookies de OpenID y OpenID connect y en consecuencia, obtener información sensible mediante URL modificadas. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI23430 http://www-01.ibm.com/support/docview.wss?uid=swg21690185 https://exchange.xforce.ibmcloud.com/vulnerabilities/97713 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-6176
https://notcve.org/view.php?id=CVE-2014-6176
IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher. IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, y Business Process Manager Advanced 7.5.x hasta 7.5.1.2, 8.0.x hasta 8.0.1.3, y 8.5.x hasta 8.5.5 desatienden la configuración SSL setting en el enlace de importación de HTTP del módulo SCA y seleccionan incondicionalmente el protocolo SSLv3, lo que facilita a atacantes remotos secuestrar sesiones o obtener información sensible a través del aprovechamiento del uso de un cifrado débil. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR51593 http://www-01.ibm.com/support/docview.wss?uid=swg21690780 http://www.securitytracker.com/id/1031382 http://www.securitytracker.com/id/1031383 https://exchange.xforce.ibmcloud.com/vulnerabilities/98488 • CWE-310: Cryptographic Issues •
CVE-2014-6138
https://notcve.org/view.php?id=CVE-2014-6138
The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to bypass intended grid-data access restrictions via unspecified vectors. El dispositivo IBM WebSphere DataPower XC10 2.1 y 2.5 anterior a FP4 permite a usuarios remotos autenticados evadir las restricciones de acceso a los datos de red a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT04614 http://www-01.ibm.com/support/docview.wss?uid=swg21691035 https://exchange.xforce.ibmcloud.com/vulnerabilities/96852 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-6215
https://notcve.org/view.php?id=CVE-2014-6215
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 before 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en IBM WebSphere Portal 6.1.0 hasta 6.1.0.6 CF27, 6.1.5 hasta 6.1.5.3 CF27, 7.0.0 anterior a 7.0.0.2 CF29, 8.0.0 hasta 8.0.0.1 CF14, y 8.5.0 anterior a CF03 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI24434 http://www-01.ibm.com/support/docview.wss?uid=swg21691458 https://exchange.xforce.ibmcloud.com/vulnerabilities/98802 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-6143
https://notcve.org/view.php?id=CVE-2014-6143
The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows local users to obtain sensitive information by reading a response. El dispositivo IBM WebSphere DataPower XC10 2.1 y 2.5 anterior a FP4 permite a usuarios locales obtener información sensible mediante la lectura de una respuesta. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT04614 http://www-01.ibm.com/support/docview.wss?uid=swg21691035 https://exchange.xforce.ibmcloud.com/vulnerabilities/96913 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •