Page 4 of 210 results (0.008 seconds)

CVSS: 7.1EPSS: 1%CPEs: 58EXPL: 0

IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool. IBM WebSphere Application Server (WAS) 6.1.0.0 hasta 6.1.0.47 y 6.0.2.0 hasta 6.0.2.43 permite a atacantes remotos causar una denegación de servicio a través de trafico TLS manipulado, tal y como fue demostrado por trafico de una herramienta de asesoramiento de vulnerabilidad de CVE-2014-0160. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI14306 http://www-01.ibm.com/support/docview.wss?uid=swg1PI16981 http://www-01.ibm.com/support/docview.wss?uid=swg1PI17128 http://www-01.ibm.com/support/docview.wss?uid=swg21671835 http://www-304.ibm.com/support/docview.wss? • CWE-399: Resource Management Errors •

CVSS: 3.5EPSS: 0%CPEs: 41EXPL: 0

Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad cross-site scripting (XSS) en Administrative Console de IBM WebSphere Application Server 7.x anteriores a 7.0.0.31, 8.0.x anteriores a 8.0.0.8, y 8.5.x anteriores a 8.5.5.2 permite a usuarios remotos autenticados inyectar script web o HTML de forma arbitraria a través de una URL manipulada. • http://osvdb.org/102119 http://www-01.ibm.com/support/docview.wss?uid=swg1PM98132 http://www-01.ibm.com/support/docview.wss?uid=swg21661323 http://www-01.ibm.com/support/docview.wss?uid=swg21661325 http://www-01.ibm.com/support/docview.wss?uid=swg21669554 http://www.securityfocus.com/bid/65099 https://exchange.xforce.ibmcloud.com/vulnerabilities/89280 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 29EXPL: 0

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad XSS en la consola administrativa en IBM WebSphere Application Server (WAS) v6.1 anterior a v6.1.0.47 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PM73445 http://www.ibm.com/support/docview.wss?uid=swg21647522 https://exchange.xforce.ibmcloud.com/vulnerabilities/83608 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.8EPSS: 0%CPEs: 87EXPL: 0

The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, when a trust store is configured for XML Digital Signatures, does not properly verify X.509 certificates, which allows remote attackers to obtain privileged access via unspecified vectors. La implementación WS-Security en IBM WebSphere Application (WAS) 6.1 (anteriores a 6.1.0.47), 7.0 (anteriores a 7.0.0.31), 8.0 (anteriores a 8.5.5.1) y WAS Feature Pack para Web Services 6.1 (anteriores a 6.1.0.47), cuando un almacén de confianza es configurado para Firmas Digitales XML, no verifica certificados X.509 apropiadamente, lo que permite a atacantes remotos obtener acceso con privilegios a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PM90949 http://www-01.ibm.com/support/docview.wss?uid=swg1PM91521 http://www.ibm.com/support/docview.wss?uid=swg21647522 https://exchange.xforce.ibmcloud.com/vulnerabilities/86505 • CWE-20: Improper Input Validation •

CVSS: 4.3EPSS: 0%CPEs: 68EXPL: 0

Cross-site scripting (XSS) vulnerability in the UDDI Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad cross-site scripting (XSS) en la consola administrativa UDDI de IBM WebSphere Application Server (WAS) 6.1 (anteriores a 6.1.0.47), 7.0 (anteriores a 7.0.0.31), 8.0 (anteriores a 8.0.0.8) y 8.5 (anteriores a 8.5.5.1) permite a un atacante remoto inyectar script web o HTML a discrección a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PM91892 http://www.ibm.com/support/docview.wss?uid=swg21647522 https://exchange.xforce.ibmcloud.com/vulnerabilities/86504 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •