CVE-2011-0527
https://notcve.org/view.php?id=CVE-2011-0527
VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during JMX authentication, which makes it easier for context-dependent attackers to obtain access by leveraging an ability to read stored passwords. VMware vFabric tc Server (también conocido como SpringSource tc Server) v2.0.x anterior a v2.0.6.RELEASE y v2.1.x anterior a v2.1.2.RELEASE acepta passwords ofuscados durante la autenticación JMX, lo que hace más fácil para atacantes dependientes del contexto obtener acceso mediante la lectura contraseñas almacenadas. • http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0122.html http://securitytracker.com/id?1025923 http://www.securityfocus.com/bid/49122 http://www.springsource.com/security/cve-2011-0527 https://exchange.xforce.ibmcloud.com/vulnerabilities/69156 • CWE-287: Improper Authentication •
CVE-2009-2907 – SpringSource (Multiple Products) - Multiple HTML Injection Vulnerabilities
https://notcve.org/view.php?id=CVE-2009-2907
Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) before 2.0.0.SR4, Hyperic HQ Open Source before 4.2.x, Hyperic HQ 4.0 Enterprise before 4.0.3.2, and Hyperic HQ 4.1 Enterprise before 4.1.2.1 allow remote attackers to inject arbitrary web script or HTML via the description field and unspecified "input fields." Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados en SpringSource tc Server v6.0.20.B y anteriores, Application Management Suite (AMS) anterior a v2.0.0.SR4, Hyperic HQ Open Source anterior a v4.2.x, Hyperic HQ v4.0 Enterprise anterior a v4.0.3.2, e Hyperic HQ v4.1 Enterprise anterior a v4.1.2.1, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del campo "description" y en campos de entrada no especificados. SpringSource Hyperic HQ suffers from multiple stored cross site scripting vulnerability. • https://www.exploit-db.com/exploits/33794 http://www.securityfocus.com/bid/38913 http://www.springsource.com/security/cve-2009-2907 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •