CVE-2019-4537
https://notcve.org/view.php?id=CVE-2019-4537
IBM WebSphere Service Registry and Repository 8.5 could allow a user to obtain sensitive version information that could be used in further attacks against the system. IBM X-Force ID: 165593. IBM WebSphere Service Registry and Repository versión 8.5, podría permitir a un usuario obtener información confidencial de la versión que podría ser usada en futuros ataques contra el sistema. IBM X-Force ID: 165593. • https://exchange.xforce.ibmcloud.com/vulnerabilities/165593 https://www.ibm.com/support/pages/node/3436359 •
CVE-2014-6160
https://notcve.org/view.php?id=CVE-2014-6160
IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation. IBM WebSphere Service Registry y Repository (WSRR) 8.5 anterior a 8.5.0.1, cuando se usan Chrome y WebSEAL, no procesa adecuadamente ServiceRegistryDashboard las acciones de logout, lo que permite a atacantes saltarse las restricciones de acceso aprovechando una estación de trabajo desatendida. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV63498 http://www-01.ibm.com/support/docview.wss?uid=swg21693389 https://exchange.xforce.ibmcloud.com/vulnerabilities/97709 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2014-6153
https://notcve.org/view.php?id=CVE-2014-6153
The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. La interfaz de usuario web en IBM WebSphere Service Registry y Repository (WSRR) 6.3.x a través de 6.3.0.5, 7.0.x a través de7.0.0.5, 7.5.x a través de7.5.0.4, 8.0.x anterior a 8.0.0.3, y 8.5.x anterior a 8.5.0.1 no establece el indicador de seguridad en una cookie de sesión https, lo cual hace más fácil a atacantes remotos capturar dicha cookie interceptando la transmisión dentro de una sesión http. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV64010 http://www.ibm.com/support/docview.wss?uid=swg21693379 http://www.ibm.com/support/docview.wss?uid=swg21693381 http://www.ibm.com/support/docview.wss?uid=swg21693384 http://www.ibm.com/support/docview.wss? • CWE-310: Cryptographic Issues •
CVE-2014-6155
https://notcve.org/view.php?id=CVE-2014-6155
Multiple directory traversal vulnerabilities in the ServiceRegistry UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allow remote authenticated users to read arbitrary files via unspecified vectors. Vulnerabilidades múltiples de salto de directorio en IBM WebSphere Service Registry and Repository (WSRR) 7.5.x a través de 7.5.0.4, 8.0.x anterior a 8.0.0.3, y 8.5.x anterior a 8.5.0.1 permite a usuarios remotos autenticados leer ficheros arbitrarios a través de vectores sin especificar. • http://secunia.com/advisories/61805 http://www-01.ibm.com/support/docview.wss?uid=swg1IV63585 http://www.ibm.com/support/docview.wss?uid=swg21693384 http://www.ibm.com/support/docview.wss?uid=swg21693387 http://www.ibm.com/support/docview.wss?uid=swg21693389 https://exchange.xforce.ibmcloud.com/vulnerabilities/97678 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2014-6132
https://notcve.org/view.php?id=CVE-2014-6132
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad XSS en IBM WebSphere Service Registry y Repository (WSRR) 6.3 a través de 6.3.0.5, 7.0.x a través de 7.0.0.5, 7.5.x a través de 7.5.0.4, 8.0.x anterior a 8.0.0.3, y 8.5.x anterior a 8.5.0.1 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de vectores sin especificar. • http://secunia.com/advisories/61805 http://www-01.ibm.com/support/docview.wss?uid=swg1IV64000 http://www.ibm.com/support/docview.wss?uid=swg21693379 http://www.ibm.com/support/docview.wss?uid=swg21693381 http://www.ibm.com/support/docview.wss?uid=swg21693384 http://www.ibm.com/support/docview.wss? • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •