9 results (0.004 seconds)

CVSS: 6.2EPSS: 0%CPEs: 4EXPL: 0

10 Sep 2018 — IBM OpenPages GRC Platform 7.2, 7.3, 7.4, and 8.0 could allow an attacker to obtain sensitive information from error log files. IBM X-Force ID: 134001. IBM OpenPages GRC Platform 7.2, 7.3, 7.4 y 8.0 podría permitir que un atacante obtenga información sensible de archivos de registro de errores. IBM X-Force ID: 134001 • https://exchange.xforce.ibmcloud.com/vulnerabilities/134001 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.0EPSS: 0%CPEs: 3EXPL: 0

30 Aug 2018 — IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303. IBM OpenPages GRC Platform 7.1, 7.2 y 7.3 podría permtir que un usuario local obtenga información sensible cuando un usuario anterior ha cerrado su sesión en el sistema, pero no ha cerrado su navegador. IBM X-Force ID: 110303. • http://www-01.ibm.com/support/docview.wss?uid=swg21997687 • CWE-613: Insufficient Session Expiration •

CVSS: 5.4EPSS: 0%CPEs: 10EXPL: 0

01 Nov 2017 — IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114711. La plataforma OpenPages GRC de IBM 7.1, 7.2 y 7.3 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que al... • http://www.ibm.com/support/docview.wss?uid=swg21997685 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 10EXPL: 0

01 Nov 2017 — IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including private APIs that could be used in further attacks against the system. IBM X-Force ID: 122201. La plataforma OpenPages GRC de IBM 7.2 y 7.3 con la aplicación OpenPages Loss Event Entry (LEE) podría permitir que un usuario obtenga información sensible, incluidas API privadas, que podrían utilizarse en otros ataques contra el sistema. IBM X-Force ID: 122201. • http://www.ibm.com/support/docview.wss?uid=swg22009717 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.4EPSS: 0%CPEs: 10EXPL: 0

01 Nov 2017 — IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122200. La plataforma OpenPages GRC de IBM 7.1, 7.2 y 7.3 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que al... • http://www.ibm.com/support/docview.wss?uid=swg21997685 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 10EXPL: 0

01 Nov 2017 — IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used in future attacks against the system. IBM X-Force ID: 126241. La plataforma OpenPages GRC de IBM, en sus versiones 7.1, 7.2 y 7.3 podría permitir que un usuario no autenticado obtenga información sensible sobre el servidor que podría utilizarse en futuros ataques contra el sistema. IBM X-Force ID: 126241. • http://www.ibm.com/support/docview.wss?uid=swg21997796 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 8.8EPSS: 0%CPEs: 10EXPL: 0

01 Nov 2017 — IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 125162. La plataforma OpenPages GRC de IBM, en sus versiones 7.1, 7.2 y 7.3 es vulnerable a ataques de tipo Cross-Site Request Forgery (CSRF). Esto podría permitir que un atacante ejecute acciones maliciosas y no autorizadas transmitidas desde un usuario en el que la web confía. IB... • http://www.ibm.com/support/docview.wss?uid=swg22009684 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 5.4EPSS: 0%CPEs: 10EXPL: 0

01 Nov 2017 — IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125151. La plataforma OpenPages GRC de IBM 7.1, 7.2 y 7.3 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que al... • http://www.ibm.com/support/docview.wss?uid=swg22009770 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 3EXPL: 0

24 Oct 2017 — IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 114712. IBM OpenPages GRC Platform 7.1, 7.2 y 7.3 es vulnerable a inyección HTML. Un atacante remoto podría inyectar código HTML malicioso que, una vez que se visualice, se ejecutaría en el navegador web de la víctima en el contexto de seguridad del si... • http://www.ibm.com/support/docview.wss?uid=swg21997686 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •