CVE-2018-1380
https://notcve.org/view.php?id=CVE-2018-1380
IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077. IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5 y 11.6 podría permitir que un usuario autenticado con acceso de nivel CA acceda para cambiar su ca-id por el de otro usuario y leer información sensible. IBM X-Force ID: 138077. • https://exchange.xforce.ibmcloud.com/vulnerabilities/138077 https://www.ibm.com/support/docview.wss?uid=ibm10735411 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2015-7423
https://notcve.org/view.php?id=CVE-2015-7423
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 107771. Múltiples vulnerabilidades de Cross-Site Scripting (XSS) en las versiones 9.1,10.1,11.0,11.3 y 11.4 de IBM InfoSphere Master Data Management (MDM)- Collaborative Edition permiten que usuarios autenticados remotos inyecten scripts web o HTML arbitrarios mediante vectores sin especificar. IBM X-Force ID: 107771. • http://www-01.ibm.com/support/docview.wss?uid=swg21971543 http://www.securityfocus.com/bid/103687 https://exchange.xforce.ibmcloud.com/vulnerabilities/107771 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-7424
https://notcve.org/view.php?id=CVE-2015-7424
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access. IBM X-Force ID: 107780. Las versiones 9.1,10.1, 11.0, 11.3,11.4 y 11.5 de IBM InfoSphere Data Management (MDM) - Collaborative Edition permiten a usuarios autenticados remotos omitir las restricciones de acceso previstas y obtener información sensible aprovechando el acceso a Catalogs. IBM X-Force ID: 107780. • http://www-01.ibm.com/support/docview.wss?uid=swg21971542 https://exchange.xforce.ibmcloud.com/vulnerabilities/107780 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-1199
https://notcve.org/view.php?id=CVE-2017-1199
IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123674. Las versiones 10.0, 11.0, 11.3, 11.4, 11.5 y 11.6 de IBM InfoSphere Master Data Management Server son vulnerables a ataques de tipo cross-site scripting. Esta vulnerabilidad permite a los usuarios introducir código JavaScript arbitrario en la interfaz de usuario de la web, lo que altera la funcionalidad prevista y puede dar lugar a la revelación de credenciales en una sesión fiable. • http://www.ibm.com/support/docview.wss?uid=swg22006618 http://www.securityfocus.com/bid/100129 https://exchange.xforce.ibmcloud.com/vulnerabilities/123674 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-9718
https://notcve.org/view.php?id=CVE-2016-9718
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119732. IBM InfoSphere Master Data Management Server versiones 10.1. 11.0. 11.3, 11.4, 11.5 y 11.6, es vulnerable a ataques de tipo cross-site scripting (XSS). Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitrario en la Web UI, lo que altera la funcionalidad prevista que potencialmente conllevaría a la divulgación de credenciales dentro de una sesión de confianza. • http://www.ibm.com/support/docview.wss?uid=swg22006606 http://www.securityfocus.com/bid/100016 https://exchange.xforce.ibmcloud.com/vulnerabilities/119732 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •