Page 18 of 212 results (0.010 seconds)

CVSS: 6.8EPSS: 0%CPEs: 54EXPL: 0

The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors. La configuración por defecto de WebSphere Application Server (WAS) de IBM 7.0.0 anteriores a 7.0.0.39, 8.0.0 anteriores a 8.0.0.11 y 8.5 anteriores a 8.5.5.6, posee un valor falso en la propiedad del contenedor web com.ibm.ws.webcontainer.disallowServeServletsByClassname, lo que permite a un atacante remoto obtener privilegios a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI31622 http://www-01.ibm.com/support/docview.wss?uid=swg21959083 http://www-01.ibm.com/support/docview.wss?uid=swg21963275 http://www.securityfocus.com/bid/75486 http://www.securitytracker.com/id/1033383 • CWE-284: Improper Access Control •

CVSS: 10.0EPSS: 0%CPEs: 78EXPL: 0

IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session. IBM WebSphere Application Server (WAS) 6.1 hasta 6.1.0.47, 7.0 anterior a 7.0.0.39, 8.0 anterior a 8.0.0.11, y 8.5 anterior a 8.5.5.6 permite a atacantes remotos ejecutar código arbitrario mediante el envío de instrucciones manipuladas en una sesión management-port. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI38302 http://www-01.ibm.com/support/docview.wss?uid=swg21883573 http://www.securityfocus.com/bid/74439 http://www.securitytracker.com/id/1032249 • CWE-284: Improper Access Control •

CVSS: 9.3EPSS: 0%CPEs: 37EXPL: 0

WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors. WebSphereOauth20SP.ear en IBM WebSphere Application Server (WAS) 7.0 anterior a 7.0.0.39, 8.0 anterior a 8.0.0.11, 8.5 Liberty Profile anterior a 8.5.5.5, y 8.5 Full Profile anterior a 8.5.5.6, cuando el tipo de cesión OAuth requiere el envío de una contraseña, permite a atacantes remotos ganar privilegios a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI33202 http://www-01.ibm.com/support/docview.wss?uid=swg1PI36211 http://www-01.ibm.com/support/docview.wss?uid=swg21697368 http://www-01.ibm.com/support/docview.wss?uid=swg21963275 http://www.securityfocus.com/bid/74219 http://www.securitytracker.com/id/1032190 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.0EPSS: 0%CPEs: 57EXPL: 0

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method. IBM WebSphere Application Server (WAS) 7.0 anterior a 7.0.0.35, 8.0 anterior a 8.0.0.10, y 8.5 anterior a 8.5.5.4 no maneja correctamente las cabeceras HTTP, lo que permite a atacantes remotos obtener datos sensibles de cookies y la autenticación a través de un método HTTP no especificado. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI08268 http://www-01.ibm.com/support/docview.wss?uid=swg21684612 https://exchange.xforce.ibmcloud.com/vulnerabilities/93059 • CWE-20: Improper Input Validation •

CVSS: 6.0EPSS: 0%CPEs: 120EXPL: 0

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de CSRF en la consola de administración en IBM WebSphere Application Server (WAS) 6.x hasta 6.1.0.47, 7.0 anterior a 7.0.0.35, 8.0 anterior a 8.0.0.10 y 8.5 anterior a 8.5.5.4 permite a usuarios remotos autenticados secuestrar la autenticación de usuarios arbitrarios para solicitudes que insertan secuencias XSS. • http://secunia.com/advisories/61418 http://secunia.com/advisories/61423 http://www-01.ibm.com/support/docview.wss?uid=swg1PI23055 http://www-01.ibm.com/support/docview.wss?uid=swg21682767 http://www.kb.cert.org/vuls/id/573356 http://www.securityfocus.com/bid/69980 https://exchange.xforce.ibmcloud.com/vulnerabilities/95402 • CWE-352: Cross-Site Request Forgery (CSRF) •