Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2016-9000

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.
0
Attacker Value
Unknown

CVE-2016-8999

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.
0
Attacker Value
Unknown

CVE-2016-8982

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
0
Attacker Value
Unknown

CVE-2015-1900

Disclosure Date: June 29, 2015 (last updated October 05, 2023)
IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-0701

Disclosure Date: January 31, 2013 (last updated October 05, 2023)
The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 rely on client-side access control, which allows remote authenticated users to gain privileges via unspecified vectors.
0