CVE-2016-9000
https://notcve.org/view.php?id=CVE-2016-9000
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks. IBM InfoSphere DataStage es vulnerable a las secuencias de comandos de trama cruzada, provocadas por la insuficiente protección HTML de iframe. Un atacante remoto podría explotar esta vulnerabilidad utilizando una URL manipulada para navegar a una página web que controla el atacante. • http://www.ibm.com/support/docview.wss?uid=swg21995257 http://www.securityfocus.com/bid/95324 http://www.securitytracker.com/id/1037564 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-8982
https://notcve.org/view.php?id=CVE-2016-8982
IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM InfoSphere Information Server almacena información sensible en parámetros de URL. Esto puede conducir a la divulgación de información si las partes no autorizadas tienen acceso a las URL a través de los registros del servidor, el encabezado de referencia o el historial del navegador. • http://www.ibm.com/support/docview.wss?uid=swg21995895 http://www.securityfocus.com/bid/95651 http://www.securitytracker.com/id/1037616 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-8999
https://notcve.org/view.php?id=CVE-2016-8999
IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS. IBM InfoSphere Information Server contiene una vulnerabilidad de importación a la hoja de estilo relativa a la ruta que permite a atacantes procesar una página en modo qirks, lo que facilita a un atacante inyectar CSS malicioso. • http://www.ibm.com/support/docview.wss?uid=swg21995155 http://www.securityfocus.com/bid/95325 http://www.securitytracker.com/id/1037563 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-1900
https://notcve.org/view.php?id=CVE-2015-1900
IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors. IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, y 11.3 hasta 11.3.1.2 en UNIX permite a usuarios locales escribir en ficheros ejecutables, y como consecuencia obtener privilegios root, a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR52770 http://www-01.ibm.com/support/docview.wss?uid=swg21902280 http://www.securityfocus.com/bid/75481 • CWE-264: Permissions, Privileges, and Access Controls •