CVE-2014-0961
https://notcve.org/view.php?id=CVE-2014-0961
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de CSRF en IBM Tivoli Identity Manager (ITIM) 5.0 anterior a 5.0.0.15 y 5.1 anterior a 5.1.0.15 y IBM Security Identity Manager (ISIM) 6.0 anterior a 6.0.0.2 permite a usuarios remotos autenticados secuestrar la autenticación de usuarios arbitrarios para solicitudes que insertan secuencias de XSS. • http://secunia.com/advisories/59080 http://www-01.ibm.com/support/docview.wss?uid=swg21674754 http://www.securityfocus.com/bid/67909 https://exchange.xforce.ibmcloud.com/vulnerabilities/92747 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2009-2583
https://notcve.org/view.php?id=CVE-2009-2583
Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces. Múltiples vulnerabilidades de fijación de sesión en IBM Tivoli Identity Manager (ITIM) v5.0.0.6 permite a atacantes remotos secuestrar sesiones web mediante vectores no definidos relacionados con (1)la consola y (2) la interfaz de servicio. • http://secunia.com/advisories/35931 http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55659 http://www-01.ibm.com/support/docview.wss?uid=swg24023826 http://www.securityfocus.com/bid/35779 http://www.securitytracker.com/id?1022597 http://www.vupen.com/english/advisories/2009/1990 • CWE-20: Improper Input Validation •