22 results (0.003 seconds)

CVSS: 5.4EPSS: 0%CPEs: 10EXPL: 0

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604. Vulnerabilidad de Cross-Site Scripting (XSS) en IBM Curam Social Program Management, en versiones 6.0.0 anteriores a SP2 EP29; versiones 6.0.4 anteriores a la 6.0.4.6 iFix3; versiones 6.0.5 anteriores a la 6.0.5.9 iFix2; versiones 6.1.0 anteriores a la la 6.1.01 iFix1 y IBM Care Management 6.0 permite que atacantes remotos inyecten scripts web o HTML arbitrarios mediante vectores sin especificar. IBM X-Force ID: 110604. • http://www-01.ibm.com/support/docview.wss?uid=swg21981103 https://exchange.xforce.ibmcloud.com/vulnerabilities/110604 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 13EXPL: 0

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 98568. Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en las versiones 6.0 SP2, 6.0.4 y 6.0.5 de IBM Curam Social Program Management permite a atacantes remotos inyectar scripts web o HTML arbitrarios utilizando vectores no especificados. IBM X-Force ID: 98568. • http://www-01.ibm.com/support/docview.wss?uid=swg21698430 http://www.securityfocus.com/bid/73946 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 39EXPL: 0

IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123670. IBM Curam Social Program Management 6.0, 6.1, 6.2, y 7.0 podría permitir que un atacante remoto lleve a cabo ataques de phishing empleando un ataque de redirección abierta. • http://www.ibm.com/support/docview.wss?uid=swg22007160 https://exchange.xforce.ibmcloud.com/vulnerabilities/123670 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 5.4EPSS: 0%CPEs: 39EXPL: 0

IBM Curam Social Program Management 6.0, 6.1, 6.2 and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119761. IBM Curam Social Program Management 6.0, 6.1, 6.2 y 7.0 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, alterando las funcionalidades planeadas. • http://www.ibm.com/support/docview.wss?uid=swg22007156 https://exchange.xforce.ibmcloud.com/vulnerabilities/119761 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 39EXPL: 0

IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the incidents of a higher privileged user. IBM X-Force ID: 120915. IBM Curam Social Program Management 6.0, 6.1, 6.2 y 7.0 contiene una vulnerabilidad no especificada que podría permitir que un usuario autenticado visualice los incidentes de un usuario con más privilegios. IBM X-Force ID: 120915. • http://www.ibm.com/support/docview.wss?uid=swg22007161 https://exchange.xforce.ibmcloud.com/vulnerabilities/120915 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •