CVE-2016-6059
https://notcve.org/view.php?id=CVE-2016-6059
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM InfoSphere Information Server es vulnerable para una denegación de servicio, provocado por un error XML External Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información altamente sensible o consumir todos los recursos de memoria disponibles. • http://www.ibm.com/support/docview.wss?uid=swg21991683 http://www.securityfocus.com/bid/94032 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2016-0280
https://notcve.org/view.php?id=CVE-2016-0280
Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and InfoSphere Information Governance Catalog 11.3 before 11.3.1.2, and Information Server Framework and InfoSphere Information Governance Catalog 11.5 before 11.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en IBM Information Server Framework 8.5, Information Server Framework e InfoSphere Information Server Business Glossary 8.7 en versiones anteriores a FP2, Information Server Framework e InfoSphere Information Server Business Glossary 9.1 en versiones anteriores a 9.1.2.0, Information Server Framework e InfoSphere Information Governance Catalog 11.3 en versiones anteriores a 11.3.1.2 e Information Server Framework e InfoSphere Information Governance Catalog 11.5 en versiones anteriores a 11.5.0.1 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR55452 http://www-01.ibm.com/support/docview.wss?uid=swg21981766 http://www.securityfocus.com/bid/92133 http://www.securitytracker.com/id/1036418 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-7490
https://notcve.org/view.php?id=CVE-2015-7490
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie. IBM InfoSphere Information Server 8.5 hasta la versión FP3, 8.7 hasta la versión FP2, 9.1 hasta la versión 9.1.2.0, 11.3 hasta la versión 11.3.1.2 y 11.5 permite a usuarios remotos autentificados eludir las restricciones destinadas al acceso a través de una cookie modificada. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR54787 http://www-01.ibm.com/support/docview.wss?uid=swg21975827 http://www.securitytracker.com/id/1035125 • CWE-284: Improper Access Control •
CVE-2015-5021
https://notcve.org/view.php?id=CVE-2015-5021
IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors. IBM InfoSphere Information Server 11.3 y 11.5 permite a los usuarios remotos autenticados DataStage eludir las restricciones destinadas a ejecución de tarea u obtener información sensible a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR54224 http://www-01.ibm.com/support/docview.wss?uid=swg21968195 http://www.securitytracker.com/id/1034043 • CWE-264: Permissions, Privileges, and Access Controls •