CVE-2017-3801

CVE-2017-3801

A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary workflow items with just an end-user profile, a Privilege Escalation Vulnerability. The vulnerability is due to improper role-based access control (RBAC) after the Developer Menu is enabled in Cisco UCS Director. An attacker could exploit this vulnerability by enabling Developer Mode for his/her user profile with an end-user profile and then adding new catalogs with arbitrary workflow items to his/her profile. An exploit could allow an attacker to perform any actions defined by these workflow items, including actions affecting other tenants. Cisco Bug IDs: CSCvb64765.

Source: CVE-2017-3801

CVE-2016-8968 (rational_collaborative_lifecycle_management)

CVE-2016-8968 (rational_collaborative_lifecycle_management)

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998515.

Source: CVE-2016-8968 (rational_collaborative_lifecycle_management)

CVE-2016-9706 (integration_bus, websphere_message_broker)

CVE-2016-9706 (integration_bus, websphere_message_broker)

IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997918.

Source: CVE-2016-9706 (integration_bus, websphere_message_broker)

CVE-2016-9010 (integration_bus, websphere_message_broker)

CVE-2016-9010 (integration_bus, websphere_message_broker)

IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim’s click actions and possibly launch further attacks against the victim. IBM Reference #: 1997906.

Source: CVE-2016-9010 (integration_bus, websphere_message_broker)