CVE-2021-20492
https://notcve.org/view.php?id=CVE-2021-20492
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793. IBM WebSphere Application Server versiones 8.0, 8.5, 9.0 y Liberty Java Batch es vulnerable a un ataque de tipo XML External Entity Injection (XXE) cuando procesa datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información confidencial o consumir recursos de memoria. • https://exchange.xforce.ibmcloud.com/vulnerabilities/197793 https://www.ibm.com/support/pages/node/6456017 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2020-4590
https://notcve.org/view.php?id=CVE-2020-4590
IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650. IBM WebSphere Application Server Liberty versiones 17.0.0.3 hasta 20.0.0.9, ejecutando las funcionalidades de servidor oauth-2.0 o openidConnectServer-1.0, es vulnerable a un ataque de denegación de servicio conducido por un cliente autenticado. IBM X-Force ID: 184650 • https://exchange.xforce.ibmcloud.com/vulnerabilities/184650 https://www.ibm.com/support/pages/node/6333623 •
CVE-2020-4421
https://notcve.org/view.php?id=CVE-2020-4421
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084. IBM WebSphere Application Liberty versiones 19.0.0.5 hasta 20.0.0.4, podría permitir a un usuario autenticado que usa openidconnect falsificar la identificación de otros usuarios. ID de IBM X-Force: 180084. • https://exchange.xforce.ibmcloud.com/vulnerabilities/180084 https://www.ibm.com/support/pages/node/6205926 • CWE-290: Authentication Bypass by Spoofing •
CVE-2020-10693 – hibernate-validator: Improper input validation in the interpolation of constraint error messages
https://notcve.org/view.php?id=CVE-2020-10693
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages. Se encontró un fallo en Hibernate Validator versión 6.1.2.Final. Un error en el procesador de interpolación de mensajes permite evaluar expresiones EL no válidas como si fueran válidas. • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10693 https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3E https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3E https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3E https://www.oracle.com/security-alerts/cpuapr2022.html https://access.redhat.com/security/cve/CVE-202 • CWE-20: Improper Input Validation •
CVE-2020-4329
https://notcve.org/view.php?id=CVE-2020-4329
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenticated attacker to obtain sensitive information, caused by improper parameter checking. This could be exploited to conduct spoofing attacks. IBM X-Force ID: 177841. IBM WebSphere Application Server versión 7.0, 8.0, 8.5, 9.0 y Liberty versiones 17.0.0.3 hasta 20.0.0.4, podrían permitir a un atacante remoto autentificado obtener información confidencial, causado por la comprobación de parámetros inapropiada. Esto podría ser explotado para llevar a cabo ataques de suplantación de identidad. • https://exchange.xforce.ibmcloud.com/vulnerabilities/177841 https://www.ibm.com/support/pages/node/6201862 •