Page 22 of 424 results (0.003 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455. IBM WebSphere Application Server Liberty podría permitir que un atacante remoto obtenga información sensible, provocado por la imposibilidad de cifrar las comunicaciones ORB. IBM X-Force ID: 145455. • http://www.securitytracker.com/id/1041720 https://exchange.xforce.ibmcloud.com/vulnerabilities/145455 https://www.ibm.com/support/docview.wss?uid=ibm10716533 • CWE-311: Missing Encryption of Sensitive Data •

CVSS: 5.9EPSS: 0%CPEs: 2EXPL: 0

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to perform man-in-the-middle attacks. IBM X-Force ID: 147292. IBM WebSphere Application Server 8.5 y 9.0 podría proporcionar seguridad más débil de lo esperado en ciertas condiciones. • http://www.securitytracker.com/id/1041718 https://exchange.xforce.ibmcloud.com/vulnerabilities/147292 https://www.ibm.com/support/docview.wss?uid=ibm10718837 •

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024. IBM WebSphere Application Server 7.0, 8.0, 8.5 y 9.0 podría permitir que atacantes remotos ejecuten código Java arbitrario mediante el conector SOAP con un objeto serializado desde fuentes no fiables. IBM X-Force ID: 143024. • http://www.securitytracker.com/id/1041644 https://exchange.xforce.ibmcloud.com/vulnerabilities/143024 https://www.ibm.com/support/docview.wss?uid=swg22016254 • CWE-502: Deserialization of Untrusted Data •

CVSS: 7.3EPSS: 0%CPEs: 3EXPL: 0

IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769. Las instalaciones de IBM WebSphere Application Server 7.0, 8.0 y 8.5.5 que emplean Form Login podrían permitir que un atacante remoto lleve a cabo ataques de suplantación. IBM X-Force ID: 145769. • http://www.securitytracker.com/id/1041643 https://exchange.xforce.ibmcloud.com/vulnerabilities/145769 https://www-01.ibm.com/support/docview.wss?uid=ibm10716523 • CWE-290: Authentication Bypass by Spoofing •

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is configured to permit access on non-secure (http) port and using JASPIC or JSR375 authentication. IBM WebSphere Application Server Liberty podría permitir que un atacante remoto obtenga información sensible, provocado por el uso de un transporte incorrecto cuando Liberty está configurado para emplear JASPIC (Java Authentication SPI for Containers). Esto puede ocurrir cuando Application Server está configurado para permitir el acceso en puertos (http) no seguros y mediante el uso de la autenticación JASPIC o JSR375. • http://www.securityfocus.com/bid/105150 http://www.securitytracker.com/id/1041558 https://exchange.xforce.ibmcloud.com/vulnerabilities/148597 https://www.ibm.com/support/docview.wss?uid=ibm10728689 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •