8 results (0.015 seconds)

CVSS: 5.3EPSS: 0%CPEs: 3EXPL: 0

01 Feb 2017 — IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM InfoSphere Information Server almacena información sensible en parámetros de URL. Esto puede conducir a la divulgación de información si las partes no autorizadas tienen acceso a las URL a través de los registros del servidor, el encabezado de referencia o el historial del navegador. • http://www.ibm.com/support/docview.wss?uid=swg21995895 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.1EPSS: 0%CPEs: 5EXPL: 0

01 Feb 2017 — IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks. IBM InfoSphere DataStage es vulnerable a las secuencias de comandos de trama cruzada, provocadas por la insuficiente protección HTML de iframe. Un atacante remoto podr... • http://www.ibm.com/support/docview.wss?uid=swg21995257 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 9EXPL: 0

01 Feb 2017 — IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS. IBM InfoSphere Information Server contiene una vulnerabilidad de importación a la hoja de estilo relativa a la ruta que permite a atacantes procesar una página en modo qirks, lo que facilita a un atacante inyectar CSS malicioso. • http://www.ibm.com/support/docview.wss?uid=swg21995155 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.1EPSS: 0%CPEs: 7EXPL: 0

01 Feb 2017 — IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM InfoSphere Information Server es vulnerable para una denegación de servicio, provocado por un error XML External Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exp... • http://www.ibm.com/support/docview.wss?uid=swg21991683 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 7.8EPSS: 0%CPEs: 8EXPL: 0

29 Jun 2015 — IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors. IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, y 11.3 hasta 11.3.1.2 en UNIX permite a usuarios locales escribir en ficheros ejecutables, y como consecuencia obtener privilegios root, a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR52770 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 8.8EPSS: 0%CPEs: 6EXPL: 0

31 Jan 2013 — The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 rely on client-side access control, which allows remote authenticated users to gain privileges via unspecified vectors. La aplicación cliente en el DataStage Administrator client in InfoSphere DataStage en IBM InfoSphere Information Server v8.1, v8.5 anterior a FP3, y v8.7 confia en el control de acceso del lado del cliente, lo que permite a usuarios remotos... • http://www-01.ibm.com/support/docview.wss?uid=swg21623501 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

10 Aug 2011 — IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. IBM InfoSphere Information Server v8.5 y v8.5.0.1 de Unix y Linux, como los utilizados en IBM InfoSphere DataStage v8.5 y v8.5.0.1 y otros productos, utiliza permisos débiles para los archivos especificados, lo que permite a usuarios locales conseguir privilegi... • http://secunia.com/advisories/45036 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

10 Aug 2011 — IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns incorrect ownership to unspecified files, which allows local users to gain privileges via unknown vectors. IBM InfoSphere Information Server 8.5 y 8.5.0.1 en Unix y Linux, tal como se usa en IBM InfoSphere DataStage 8.5 y 8.5.0.1 y otros productos, asigna incorrectamente la propiedad de fiheros sin especificar, lo que permite a usuarios locales escalar privileg... • http://secunia.com/advisories/45036 • CWE-264: Permissions, Privileges, and Access Controls •