Page 18 of 328 results (0.008 seconds)

CVSS: 5.0EPSS: 0%CPEs: 54EXPL: 0

IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors. Vulnerabilidad en IBM WebSphere Application Server en 7.x en versiones anteriores a 7.0.0.39, 8.0.x en versiones anteriores a 8.0.0.11, 8.5.x en versiones anteriores a 8.5.5.7, permite a atacantes remotos suplantar servlets y obtener información sensible a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI37396 http://www-01.ibm.com/support/docview.wss?uid=swg21963275 http://www.securityfocus.com/bid/76463 http://www.securitytracker.com/id/1033324 •

CVSS: 5.0EPSS: 0%CPEs: 55EXPL: 0

IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header. Vulnerabilidad en IBM WebSpher Application Server en 7.x en versiones anteriores a 7.0.0.39, 8.0.x en versiones anteriores a 8.0.0.11, 8.5.x en versiones anteriores a 8.5.5.7 y WebSphere Virtual Enterprise en versiones anteriores a 7.0.0.7, permite a atacantes remotos obtener información potencialmente sensible sobre el software del servidor proxy leyendo el HTTP a través de las cabeceras. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI38403 http://www-01.ibm.com/support/docview.wss?uid=swg21963275 http://www.securityfocus.com/bid/76466 http://www.securitytracker.com/id/1033325 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.8EPSS: 0%CPEs: 54EXPL: 0

The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors. La configuración por defecto de WebSphere Application Server (WAS) de IBM 7.0.0 anteriores a 7.0.0.39, 8.0.0 anteriores a 8.0.0.11 y 8.5 anteriores a 8.5.5.6, posee un valor falso en la propiedad del contenedor web com.ibm.ws.webcontainer.disallowServeServletsByClassname, lo que permite a un atacante remoto obtener privilegios a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI31622 http://www-01.ibm.com/support/docview.wss?uid=swg21959083 http://www-01.ibm.com/support/docview.wss?uid=swg21963275 http://www.securityfocus.com/bid/75486 http://www.securitytracker.com/id/1033383 • CWE-284: Improper Access Control •

CVSS: 4.4EPSS: 0%CPEs: 17EXPL: 0

IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors. WebSphere Application Server (WAS) 8.5 anteriores a 8.5.5.6 y WebSphere Virtual Enterprise 7.0 anteriores a 7.0.0.6 para WebSphere Application Server (WAS) 7.0 y 8.0, no tienen los roles de usuarios correctamente implementados lo que permite a un usuario local obtener privilegios a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI35180 http://www-01.ibm.com/support/docview.wss?uid=swg21959083 http://www.securityfocus.com/bid/75496 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 10.0EPSS: 0%CPEs: 78EXPL: 0

IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session. IBM WebSphere Application Server (WAS) 6.1 hasta 6.1.0.47, 7.0 anterior a 7.0.0.39, 8.0 anterior a 8.0.0.11, y 8.5 anterior a 8.5.5.6 permite a atacantes remotos ejecutar código arbitrario mediante el envío de instrucciones manipuladas en una sesión management-port. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI38302 http://www-01.ibm.com/support/docview.wss?uid=swg21883573 http://www.securityfocus.com/bid/74439 http://www.securitytracker.com/id/1032249 • CWE-284: Improper Access Control •