CVE-2024-28764 – IBM WebSphere Automation CSV injection
https://notcve.org/view.php?id=CVE-2024-28764
IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623. IBM WebSphere Automation 1.7.0 podría permitir que un atacante con acceso privilegiado a la red realice una inyección CSV. Un atacante podría ejecutar comandos arbitrarios en el sistema, causados por una validación inadecuada del contenido del archivo csv. • https://exchange.xforce.ibmcloud.com/vulnerabilities/285623 https://www.ibm.com/support/pages/node/7149857 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •
CVE-2024-28775 – IBM WebSphere Automation cross-site scripting
https://notcve.org/view.php?id=CVE-2024-28775
IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285648. IBM WebSphere Automation 1.7.0 es vulnerable a Cross Site Scripting. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría conducir a la divulgación de credenciales dentro de una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/285648 https://www.ibm.com/support/pages/node/7149856 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-43901 – IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps information disclosure
https://notcve.org/view.php?id=CVE-2022-43901
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit this vulnerability to possibly gain information to other IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps components. IBM X-Force ID: 240829. IBM WebSphere Automation para IBM Cloud Pak para Watson AIOps 1.4.3 podría revelar información confidencial. Un atacante local autenticado podría aprovechar esta vulnerabilidad para posiblemente obtener información para otros componentes de IBM WebSphere Automation para IBM Cloud Pak para Watson AIOps. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240829 https://www.ibm.com/support/pages/node/6842605 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-668: Exposure of Resource to Wrong Sphere •
CVE-2022-43900 – IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps security bypass
https://notcve.org/view.php?id=CVE-2022-43900
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827. IBM WebSphere Automation para IBM Cloud Pak para Watson AIOps 1.4.2 podría proporcionar una seguridad más débil de lo esperado. Un atacante local puede crear una conexión de red saliente a otro sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240827 https://www.ibm.com/support/pages/node/6842605 • CWE-287: Improper Authentication •
CVE-2022-22493
https://notcve.org/view.php?id=CVE-2022-22493
IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449. IBM WebSphere Automation for Cloud Pak for Watson AIOps versión 1.4.2, es vulnerable a un ataque de tipo cross-site request forgery, causada por la configuración inapropiada de los atributos de las cookies. IBM X-Force ID: 226449 • https://exchange.xforce.ibmcloud.com/vulnerabilities/226449 https://www.ibm.com/support/pages/node/6826727 • CWE-352: Cross-Site Request Forgery (CSRF) •