Page 11 of 139 results (0.011 seconds)

CVSS: 9.8EPSS: 1%CPEs: 1EXPL: 0

IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vulnerability to execute arbitrary code. IBM X-Force ID: 150999. IBM WebSphere Application Server Liberty OpenID Connect podría permitir que un atacante remoto ejecute código arbitrario en el sistema, provocado por una deserialización incorrecta. Un atacante podría explotar esta vulnerabilidad para ejecutar código arbitrario en el sistema mediante el envío de una petición especialmente manipulada al servicio RP. • http://www.securityfocus.com/bid/105839 https://exchange.xforce.ibmcloud.com/vulnerabilities/150999 https://www.ibm.com/support/docview.wss?uid=ibm10735105 • CWE-502: Deserialization of Untrusted Data •

CVSS: 6.1EPSS: 0%CPEs: 5EXPL: 0

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148621. IBM WebSphere Application Server 7.0, 8.0, 8.5 y 9.0 Cachemonitor es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.securitytracker.com/id/1041983 https://exchange.xforce.ibmcloud.com/vulnerabilities/148621 https://www.ibm.com/support/docview.wss?uid=ibm10729547 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148800. IBM WebSphere Application Server 7.0, 8.0, 8.5 y 9.0 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.securitytracker.com/id/1041873 https://exchange.xforce.ibmcloud.com/vulnerabilities/148800 https://www.ibm.com/support/docview.wss?uid=ibm10730631 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 1

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148686. IBM WebSphere Application Server 7.0, 8.0, 8.5 y 9.0 podría permitir que un atacante remoto salte directorios en el sistema. Un atacante podría enviar una petición URL especialmente manipulada que contenga secuencias "punto punto" (/../) para visualizar archivos arbitrarios en el sistema. • http://www.securitytracker.com/id/1041874 https://exchange.xforce.ibmcloud.com/vulnerabilities/148686 https://www.ibm.com/support/docview.wss?uid=ibm10729521 https://www.tenable.com/security/research/tra-2018-30 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 0

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148948. IBM WebSphere Application Server 7.0, 8.0, 8.5 y 9.0, utilizando SAML, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.securitytracker.com/id/1041801 https://exchange.xforce.ibmcloud.com/vulnerabilities/148948 https://www.ibm.com/support/docview.wss?uid=ibm10729563 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •