
CVE-2015-0110
https://notcve.org/view.php?id=CVE-2015-0110
15 Sep 2017 — IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL. IBM Business Process Manager (BPM) 7.5.x, 8.0.x y 8.5.x y WebSphere Lombardi Edition (WLE) 7.2.x permiten que usuarios autenticados remotos omitan las restricciones de acceso establecidas en tipos de servicios internos mediante vectores relacionados co... • http://www.securityfocus.com/bid/73274 • CWE-284: Improper Access Control •

CVE-2017-1501
https://notcve.org/view.php?id=CVE-2017-1501
18 Aug 2017 — IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web services security bindings settings. IBM X-Force ID: 129576. IBM WebSphere Application Server 8.0, 8.5 y 9.0 podría proporcionar una seguridad más débil de lo esperado después de usar la consola de administrador para actualizar la configuración de seguridad de los servicios web. IBM X-Force ID: 129576. • http://www.ibm.com/support/docview.wss?uid=swg22006810 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1380
https://notcve.org/view.php?id=CVE-2017-1380
24 Jul 2017 — IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127151. IBM WebSphere Application Server 7.0, 8.0, 8.5 y 9.0 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de us... • http://www.ibm.com/support/docview.wss?uid=swg22004786 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1382
https://notcve.org/view.php?id=CVE-2017-1382
24 Jul 2017 — IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153. IBM WebSphere Application Server versión 7.0,versión 8.0,versión 8.5 y versión 9.0 podría crear archivos usando los permisos por defecto en lugar de los permisos personalizados cuando se usan scripts de inicio personalizado... • http://www.ibm.com/support/docview.wss?uid=swg22004785 • CWE-276: Incorrect Default Permissions •

CVE-2017-1381
https://notcve.org/view.php?id=CVE-2017-1381
21 Jul 2017 — IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152. IBM WebSphere Application Server Proxy Server o On-demand-router (ODR) versión 7.0,versión 8.0,versión 8.5,versión 9.0 podría permitir a un atacante local obtener información confidencial, causada por el almacenamiento de datos antiguos. ID de IBM X-Force: 127152. • http://www.ibm.com/support/docview.wss?uid=swg22004792 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-9736
https://notcve.org/view.php?id=CVE-2016-9736
08 Jun 2017 — IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information. WebSphere Application Server de IBM usando peticiones SOAP malformadas podría permitir a un atacante remoto obtener información confidencial. • http://www-01.ibm.com/support/docview.wss?uid=swg21991469 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1137
https://notcve.org/view.php?id=CVE-2017-1137
10 May 2017 — IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549. IBM WebSphere Application Server versión 8.0 y versión 8.5.5 podría proporcionar una seguridad más débil de lo esperado. Un atacante remoto podría explotar esta debilidad para obtener información confidencial y obtener acceso no autorizado a la consola de administrac... • http://www.ibm.com/support/docview.wss?uid=swg21998469 •

CVE-2017-1194
https://notcve.org/view.php?id=CVE-2017-1194
28 Apr 2017 — IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669. IBM WebSphere Application Server versiones 7.0, 8.0, 8.5 y 9.0 son vulnerables a falsificación de petición en sitios cruzados (CSRF) lo que podría permitir a un atacante ejecutar acciones malintencionadas y no autorizadas transmitidas a través de un usuario que c... • http://www.ibm.com/support/docview.wss?uid=swg22001226 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2017-1151
https://notcve.org/view.php?id=CVE-2017-1151
20 Mar 2017 — IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated privileges on the system. IBM Reference #: 1999293. IBM WebSphere Application Server 8.0, 8.5, 8.5.5 y 9.0 usando OpenID Connect (OIDC) configurado con un interceptor de asociación de confianza (TAI) podría permitir a un usuario obtener elevados privilegios en el sistema. IBM Reference #: 1999293. • http://www.ibm.com/support/docview.wss?uid=swg21999293 •

CVE-2017-1121
https://notcve.org/view.php?id=CVE-2017-1121
13 Feb 2017 — IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997743 IBM WebSphere Application Server 7.0, 8.0 y 9.0 es vulnerable a las secuencias de comandos en sitios cruzados. Esta vulnerabilidad permite a los usuarios integrar código JavaScript arbitrario en la inter... • http://www.ibm.com/support/docview.wss?uid=swg21997743 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •