Page 2 of 10 results (0.006 seconds)

CVSS: 4.3EPSS: 0%CPEs: 44EXPL: 0

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a "Signature Wrap attack," a different vulnerability than CVE-2011-1377 and CVE-2013-0489. IBM WebSphere Application Server (WAS) 7.0 anterior a 7.0.0.29, 8.0 anterior a 8.0.0.6, y 8.5 a la 8.5.0.2 y WebSphere Message Broker 6.1, 7.0 a la 7.0.0.5, y 8.0 a la 8.0.0.2, cuando se usa WS-Security, permite a atacantes remotos suplantar las firmas de los mensajes a través de mensajes SOAP manipulados relacionado con "Signature Wrap attack," vulnerabilidad distinta de CVE-2011-1377 y CVE-2013-0489. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC88185 http://www-01.ibm.com/support/docview.wss?uid=swg1PM76582 http://www-01.ibm.com/support/docview.wss?uid=swg1PM86026 http://www-01.ibm.com/support/docview.wss?uid=swg21634646 http://www-01.ibm.com/support/docview.wss? •

CVSS: 2.6EPSS: 0%CPEs: 8EXPL: 0

Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is not properly handled during construction of an error message. Cross-site scripting (XSS) en WebSphere Message Broker IBM v7,0 antes de v7.0.0.6 y v8,0 antes de v8.0.0.2 antes, cuando el soporte wsdl está habilitada en un nodo SOAPInput, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de una solicitud wsdl que no se maneja adecuadamente durante la construcción de un mensaje de error. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC89383 http://www-01.ibm.com/support/docview.wss?uid=swg21623316 https://exchange.xforce.ibmcloud.com/vulnerabilities/81062 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 1%CPEs: 20EXPL: 0

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2, when the Parse Query Strings option is enabled on an HTTPInput node, allows remote attackers to cause a denial of service (infinite loop) via a crafted query string. IBM WebSphere Message Broker v6.1 antes v6.1.0.12, v7,0 antes de v7.0.0.6 y 8,0 antes de 8.0.0.2, cuando la opción de análisis de cadenas está habilitada en un nodo HTTPInput, permite a atacantes remotos provocar una denegación de servicio (bucle infinito) a través de una cadena de consulta hecha a mano . • http://www-01.ibm.com/support/docview.wss?uid=swg1PM75015 http://www-01.ibm.com/support/docview.wss?uid=swg21623316 https://exchange.xforce.ibmcloud.com/vulnerabilities/80667 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 5.0EPSS: 0%CPEs: 20EXPL: 0

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors. IBM WebSphere Message Broker v6.1 antes de v6.1.0.12, v7.0 antes de v7.0.0.6 y v8.0 antes de v8.0.0.2 no validan credenciales de autenticación básicas antes de proceder a operaciones de WS-Addressing y WS-Security, lo que permite a atacantes remotos provocar la transmisión de mensajes no autenticados a través de vectores sin especificar. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC89803 http://www-01.ibm.com/support/docview.wss?uid=swg21623316 https://exchange.xforce.ibmcloud.com/vulnerabilities/80666 • CWE-287: Improper Authentication •

CVSS: 6.9EPSS: 0%CPEs: 18EXPL: 0

IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300. IBM WebSphere Message Broker v6.1 anterior a v6.1.0.11, v7.0 anterior a v7.0.0.5, y v8.0 anterior a v8.0.0.2 tiene la propiedad incorrecta de cierto programa de desinstalación de Java Runtime Environment (JRE), lo que podría permitir a usuarios locales obtener privilegios mediante el aprovechamiento de acceso a uid 501 o gid 300. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC85477 http://www.ibm.com/support/docview.wss?uid=swg21611401 https://exchange.xforce.ibmcloud.com/vulnerabilities/77818 • CWE-264: Permissions, Privileges, and Access Controls •