Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mayank Somani

#19298de 53,639
13.7CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2018-12194
4.9
2018-10-29
Ibm · Infosphere Master Data Management Collaborative Server · CVE-2018-1380
**Name of the Vulnerable Software and Affected Versions** IBM InfoSphere Master Data Management Collaboration Server versions 11.4 through 11.6 **Description** The issue allows an authenticated user with CA level access to change their `ca-id` to another user's, potentially enabling them to read sensitive information. **Recommendations** For versions 11.4 through 11.6, restrict access to CA level functions to minimize the risk of exploitation.
PT-2017-9899
8.8
2017-03-27
Ibm · Ibm Cognos Business Intelligence · CVE-2016-8960
**Name of the Vulnerable Software and Affected Versions** IBM Cognos Business Intelligence version 10.2 **Description** The issue allows a user with lower privilege capabilities to adopt the capabilities of a higher-privilege user. This is achieved by intercepting the higher-privilege user's cookie value from its HTTP request and then reusing it in subsequent requests. **Recommendations** For IBM Cognos Business Intelligence version 10.2, consider restricting access to sensitive areas of the application to minimize the risk of exploitation until a fix is available. As a temporary workaround, review and strengthen cookie handling and session management practices to prevent unauthorized reuse of cookie values.