IBM Intelligent Operations Center Multiple Security Vulnerabilities
BID:109063
Info
IBM Intelligent Operations Center Multiple Security Vulnerabilities
| Bugtraq ID: | 109063 |
| Class: | Design Error |
| CVE: |
CVE-2019-4066 CVE-2019-4067 CVE-2019-4068 CVE-2019-4069 CVE-2019-4070 |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2019 12:00AM |
| Updated: | May 31 2019 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Water Operations for Waternamics 5.1 IBM Water Operations for Waternamics 5.2.1.1 IBM Intelligent Operations Center for Emergency Management 5.1 IBM Intelligent Operations Center for Emergency Management 5.1.0.6 IBM Intelligent Operations Center 5.2 IBM Intelligent Operations Center 5.1 |
| Not Vulnerable: | |
Discussion
IBM Intelligent Operations Center Multiple Security Vulnerabilities
IBM Intelligent Operations Center is prone to multiple security vulnerabilities.
An attacker can exploit these issues to obtain sensitive information, upload arbitrary files, harvest valid accounts, which may aid in brute-force attacks and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
IBM Intelligent Operations Center is prone to multiple security vulnerabilities.
An attacker can exploit these issues to obtain sensitive information, upload arbitrary files, harvest valid accounts, which may aid in brute-force attacks and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
References
IBM Intelligent Operations Center Multiple Security Vulnerabilities
References:
References:
- IBM Homepage (IBM)
- Security Bulletin: Cross-site scripting vulnerability in IBM® Intelligent Opera (IBM)
- Security Bulletin: IBM® Intelligent Operations Center does not correctly valida (IBM)
- Security Bulletin: IBM® Intelligent Operations Center has a weak user-creation (IBM)
- Security Bulletin: IBM® Intelligent Operations Center is vulnerable to user enu (IBM)
- Security Bulletin: User passwords might be obtained by a brute force attack on (IBM)