CVE-2018-1967
https://notcve.org/view.php?id=CVE-2018-1967
IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153748. La versión 6.0.0 de IBM Security Identity Manager es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.securityfocus.com/bid/106554 https://exchange.xforce.ibmcloud.com/vulnerabilities/153748 https://www.ibm.com/support/docview.wss?uid=ibm10794615 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-1956
https://notcve.org/view.php?id=CVE-2018-1956
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 153628. La versión 6.0.0 de IBM Security Identity Manager no requiere que los usuarios tengan contraseñas fuertes por defecto, lo que facilita que los atacantes comprometan las cuentas de usuario. IBM X-Force ID: 153628. • http://www.securityfocus.com/bid/106554 https://exchange.xforce.ibmcloud.com/vulnerabilities/153628 https://www.ibm.com/support/docview.wss?uid=ibm10794615 • CWE-521: Weak Password Requirements •
CVE-2018-1969
https://notcve.org/view.php?id=CVE-2018-1969
IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 153750. La versión 6.0.0 de IBM Security Identity Manager permite que un atacante autenticado suba o transfiera archivos de tipos peligrosos que pueden procesarse automáticamente en el entorno del producto. IBM X-Force ID: 153750. • http://www.securityfocus.com/bid/106554 https://exchange.xforce.ibmcloud.com/vulnerabilities/153750 https://www.ibm.com/support/docview.wss?uid=ibm10794615 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2017-1405
https://notcve.org/view.php?id=CVE-2017-1405
IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 127392. IBM Security Identity Manager Virtual Appliance 7.0 procesa parches, backups de imágenes y otras actualizaciones sin verificar lo suficiente el origen e integridad del código. IBM X-Force ID: 127392. • http://www.ibm.com/support/docview.wss?uid=swg22013617 https://exchange.xforce.ibmcloud.com/vulnerabilities/127392 • CWE-345: Insufficient Verification of Data Authenticity •
CVE-2018-1453
https://notcve.org/view.php?id=CVE-2018-1453
IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be automatically processed within the environment. IBM X-Force ID: 140055. IBM Security Identity Manager Virtual Appliance 7.0 permite que un atacante autenticado suba o transfiera archivos de tipos peligrosos que pueden procesarse automáticamente en el entorno. IBM X-Force ID: 140055. • http://www.ibm.com/support/docview.wss?uid=swg22013617 http://www.securitytracker.com/id/1041383 https://exchange.xforce.ibmcloud.com/vulnerabilities/140055 • CWE-434: Unrestricted Upload of File with Dangerous Type •