Page 117 of 828 results (0.010 seconds)

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to read unspecified files via unknown vectors. La funcionalidad de aplicación JavaServer Faces (JSF) de IBM WebSphere Application Server 8.x anteriores a 8.0.0.1 no maneja adecuadamente peticiones, lo que permite a atacantes remotos leer archivos sin especificar a través de vectores desconocidos. • http://www-01.ibm.com/support/docview.wss?uid=swg24030916 http://www.ibm.com/support/docview.wss?uid=swg1PM45992 https://exchange.xforce.ibmcloud.com/vulnerabilities/70168 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.3EPSS: 0%CPEs: 7EXPL: 0

IBM WebSphere MQ 7.x before 7.0.1.4 allows remote attackers to cause a denial of service (disk consumption) via multiple connection attempts to a stopped queue manager. IBM WebSphere MQ 7.x anteriores a 7.0.1.4 permite a atacantes remotos provocar una denegación de servicio (corrupción de disco) a través de intentos de conexión múltiples a un gestor de cola detenido. • http://www-01.ibm.com/support/docview.wss?uid=swg27014224 http://www.ibm.com/support/docview.wss?uid=swg1IZ75124 https://exchange.xforce.ibmcloud.com/vulnerabilities/60638 • CWE-399: Resource Management Errors •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an Unknown Error document, a different vulnerability than CVE-2011-4171. Vulnerabilidad en Cross-site scripting (XSS) en el contenido/error.jsp en IBM WebSphere ILOG Rule Team Server v7.1.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores que provocan un documento de error desconocido, una vulnerabilidad diferente a CVE-2011-4171. • http://www.ibm.com/support/docview.wss?uid=swg1RS00810 https://exchange.xforce.ibmcloud.com/vulnerabilities/71005 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the project parameter to teamserver/faces/home.jsp. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS)en content/error.jsp en IBM WebSphere ILOG Rule Team Server v7.1.1 permite a atacantes remotos inyectar código script web o HTML de su elección a través del parámetro project en teamserver/faces/home.jsp. • http://secunia.com/advisories/46350 http://securitytracker.com/id?1026170 http://www.ibm.com/support/docview.wss?uid=swg1RS00803 http://www.osvdb.org/76238 http://www.securityfocus.com/bid/50056 https://exchange.xforce.ibmcloud.com/vulnerabilities/70461 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 0%CPEs: 16EXPL: 0

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which has unspecified impact and attack vectors. IBM WebSphere Commerce v6.x a través de v6.0.0.11 y v7.0.0.3 7.x no aplica correctamente la autenticación Activity Token para Web Services, que tienen un impacto no especificado y vectores de ataque. • http://secunia.com/advisories/45999 http://www.ibm.com/support/docview.wss?uid=swg1JR40420 http://www.ibm.com/support/docview.wss?uid=swg24030908 http://www.osvdb.org/75428 http://www.securityfocus.com/bid/49643 https://exchange.xforce.ibmcloud.com/vulnerabilities/69838 • CWE-287: Improper Authentication •