Page 9 of 106 results (0.013 seconds)

CVSS: 10.0EPSS: 0%CPEs: 2EXPL: 0

IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370. IBM Security Access Manager Appliance 9.0.4.0 y 9.0.5.0 podría permitir la ejecución remota de código cuando se están ejecutando los servicios Advanced Access Control o Federation. IBM X-Force ID: 147370. • http://www.securityfocus.com/bid/105145 http://www.securitytracker.com/id/1041557 https://exchange.xforce.ibmcloud.com/vulnerabilities/147370 https://www.ibm.com/support/docview.wss?uid=ibm10719623 •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 134913. IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 no establece el atributo secure en los tokens de autorización o cookies de sesión. • http://www.ibm.com/support/docview.wss?uid=ibm10726017 https://exchange.xforce.ibmcloud.com/vulnerabilities/134913 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.9EPSS: 0%CPEs: 4EXPL: 0

IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 128610. IBM InfoSphere Information Server 7.0.0, desde la versión 8.0.0 hasta la 8.0.1.6 y desde la 9.0.0 hasta la 9.0.3.1 podría permitir que un atacante remoto obtenga información sensible, provocado por la imposibilidad de habilitar correctamente HTTP Strict Transport Security. Un atacante podría explotar esta vulnerabilidad para obtener información sensible empleando técnicas man-in-the-Middle (MitM). • http://www.ibm.com/support/docview.wss?uid=swg22012310 http://www.securityfocus.com/bid/104501 https://exchange.xforce.ibmcloud.com/vulnerabilities/128610 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617. IBM Security Access Manager Appliance desde la versión 8.0.0 hasta la 8.0.1.6 y desde la 9.0.0 hasta la 9.0.3.1 almacena información potencialmente sensible en archivos de registro que podrían ser leídos por un usuario remoto. IBM X-Force ID: 128617. • http://www.ibm.com/support/docview.wss?uid=swg22012309 http://www.securityfocus.com/bid/104471 https://exchange.xforce.ibmcloud.com/vulnerabilities/128617 • CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 5.3EPSS: 0%CPEs: 4EXPL: 0

IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606. IBM Security Access Manager Appliance 7.0.0, desde la versión 8.0.0 hasta la 8.0.1.6 y desde la 9.0.0 hasta la 9.0.3.1 revela información sensible a usuarios no autorizados. Esta información puede emplearse para ejecutar más ataques en el sistema. • http://www.ibm.com/support/docview.wss?uid=swg22012329 http://www.securityfocus.com/bid/104476 https://exchange.xforce.ibmcloud.com/vulnerabilities/128606 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •