CVE-2023-30437 – IBM Security Guardium information disclosure
https://notcve.org/view.php?id=CVE-2023-30437
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293. IBM Security Guardium 11.3, 11.4 y 11.5 podría permitir a un usuario no autorizado enumerar nombres de usuario enviando una solicitud HTTP especialmente manipulada. ID de IBM X-Force: 252293. • https://exchange.xforce.ibmcloud.com/vulnerabilities/252293 https://www.ibm.com/support/pages/node/7028506 •
CVE-2023-30436 – IBM Security Guardium cross-site scripting
https://notcve.org/view.php?id=CVE-2023-30436
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252292. IBM Security Guardium 11.3, 11.4 y 11.5 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, lo que altera la funcionalidad prevista y puede conducir a la divulgación de credenciales en una sesión de confianza. • https://exchange.xforce.ibmcloud.com/vulnerabilities/252292 https://www.ibm.com/support/pages/node/7028506 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-30435 – IBM Security Guardium cross-site scripting
https://notcve.org/view.php?id=CVE-2023-30435
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252291. IBM Security Guardium v11.3, v11.4 y v11.5 es vulnerable a Cross-Site Scripting (XSS) almacenado. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, lo que altera la funcionalidad prevista y puede conducir a la divulgación de credenciales en una sesión de confianza. • https://exchange.xforce.ibmcloud.com/vulnerabilities/252291 https://www.ibm.com/support/pages/node/7028506 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-38730 – IBM Spectrum Copy Data Management information disclosure
https://notcve.org/view.php?id=CVE-2023-38730
IBM Storage Copy Data Management 2.2.0.0 through 2.2.19.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 262268. IBM Storage Copy Data Management v2.2.0.0 hasta v2.2.19.0 utiliza algoritmos criptográficos más débiles de los esperado que podrían permitir a un atacante descifrar información altamente sensible. ID de IBM X-Force: 262268. • https://exchange.xforce.ibmcloud.com/vulnerabilities/262268 https://www.ibm.com/support/pages/node/7028841 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2023-40371 – IBM AIX information disclosure
https://notcve.org/view.php?id=CVE-2023-40371
IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper access controls. IBM X-Force ID: 263476. • https://exchange.xforce.ibmcloud.com/vulnerabilities/263476 https://www.ibm.com/support/pages/node/7028420 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-327: Use of a Broken or Risky Cryptographic Algorithm •