Page 4 of 26 results (0.003 seconds)

CVSS: 2.1EPSS: 0%CPEs: 22EXPL: 0

The command-line scripts in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 2 through 8, when debugging is configured, do not properly restrict the logging of personal data, which allows local users to obtain sensitive information by reading a log file. Las secuencias de comandos command-line en IBM WebSphere Commerce 6.0 hasta 6.0.0.11, 7.0 hasta 7.0.0.9, y 7.0 Feature Pack 2 hasta 8, cuando la depuración está configurada, no restringen correctamente el registro de datos personales, lo que permite a usuarios locales obtener información sensible mediante la lectura de un fichero de registros. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR52117 http://www-01.ibm.com/support/docview.wss?uid=swg1JR52983 http://www-01.ibm.com/support/docview.wss?uid=swg21883875 http://www.securitytracker.com/id/1032248 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.0EPSS: 0%CPEs: 21EXPL: 0

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. IBM WebSphere Commerce 6.x hasta 6.0.0.11 y 7.x hasta 7.0.0.8 permite a usuarios remotos autenticados leer ficheros arbitrarios o enviar solicitudes TCP a servidores de intranet a través de datos XML que contienen una declaración de entidad externa en conjunto con una referencia de entidad, relacionado con un problema de entidad externa XML (XXE). • http://www-01.ibm.com/support/docview.wss?uid=swg1JR49897 http://www-01.ibm.com/support/docview.wss?uid=swg1JR50553 http://www-01.ibm.com/support/docview.wss?uid=swg21685464 http://www.securityfocus.com/bid/70872 https://exchange.xforce.ibmcloud.com/vulnerabilities/94836 •

CVSS: 4.3EPSS: 0%CPEs: 21EXPL: 0

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. IBM WebSphere Commerce 6.x hasta 6.0.0.11 y 7.x hasta 7.0.0.8 no detecta debidamente la recursión durante la expansión de entidades, lo que permite a atacantes remotos causar una denegación de servicio (consumo de memoria y CPU y caída de aplicación) a través de un documento XML manipulado que contiene un número grande de referencias de entidades anidadas, un problema similar a CVE-2003-1564. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR49897 http://www-01.ibm.com/support/docview.wss?uid=swg1JR50553 http://www-01.ibm.com/support/docview.wss?uid=swg21685464 http://www.securityfocus.com/bid/70870 https://exchange.xforce.ibmcloud.com/vulnerabilities/95628 •

CVSS: 7.1EPSS: 1%CPEs: 10EXPL: 0

IBM WebSphere Commerce 6.0 Feature Pack 2 through Feature Pack 5, 7.0.0.0 through 7.0.0.8, and 7.0 Feature Pack 1 through Feature Pack 7 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a malformed id parameter in a request. IBM WebSphere Commerce 6.0 Feature Pack 2 hasta Feature Pack 5, 7.0.0.0 hasta 7.0.0.8 y 7.0 Feature Pack 1 hasta Feature Pack 7 permite a atacantes remotos causar una denegación de servicio (consumo de recursos y caída de demonio) a través de un parámetro id malformado en una solicitud. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR49881 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49996 http://www-01.ibm.com/support/docview.wss?uid=swg21671377 http://www.securitytracker.com/id/1030284 https://exchange.xforce.ibmcloud.com/vulnerabilities/92402 • CWE-20: Improper Input Validation •

CVSS: 4.3EPSS: 0%CPEs: 26EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Accelerator JSPs, (2) Organization Administration Console JSPs, and (3) Administration Console JSPs in WebSphere Commerce Tools in IBM WebSphere Commerce 5.6.1.0 through 5.6.1.5, 6.0.0.0 through 6.0.0.11, and 7.0.0.0 through 7.0.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de cross-site scripting (XSS) en (1) Accelerator JSPs, (2) Organization Administration Console JSPs, y (3) Administration Console JSPs en WebSphere Commerce Tools en IBM WebSphere Commerce c5.6.1.0 hasta v5.6.1.5, c6.0.0.0 hasta v6.0.0.11, y v7.0.0.0 hasta v7.0.0.7, permite a atacantes remotos inyectar secuencias de comandos web o HTML sin especificar a través de vectores sin especificar. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR46776 http://www.ibm.com/support/docview.wss?uid=swg21647750 https://exchange.xforce.ibmcloud.com/vulnerabilities/83139 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •