CVE-2012-4851
https://notcve.org/view.php?id=CVE-2012-4851
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en IBM WebSphere Application Server v8.5 Liberty Profile antes de v8.5.0.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de un URI diseñada para tal fin. • http://www-01.ibm.com/support/docview.wss?uid=swg1PM68643 http://www.ibm.com/support/docview.wss?uid=swg21614265 http://www.securityfocus.com/bid/56423 https://exchange.xforce.ibmcloud.com/vulnerabilities/79541 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-4850
https://notcve.org/view.php?id=CVE-2012-4850
IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote attackers to gain privileges via unspecified vectors. IBM WebSphere Application Server v8.5 Liberty Profile antes de v8.5.0.1, cuando se usa JAX-RS, no valida correctamente las solicitudes, lo que permite a atacantes remotos obtener privilegios a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PM67082 http://www.ibm.com/support/docview.wss?uid=swg21614265 http://www.securityfocus.com/bid/56460 https://exchange.xforce.ibmcloud.com/vulnerabilities/79539 • CWE-20: Improper Input Validation •
CVE-2012-3330
https://notcve.org/view.php?id=CVE-2012-3330
The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterprise, allows remote attackers to cause a denial of service (daemon outage) via a crafted request. El servidor proxy en IBM WebSphere Application Server v7.0 antes de v7.0.0.27, v8.0 antes de v8.0.0.5 y v8.5 antes de v8.5.0.1 y WebSphere Virtual Enterprise, permite a atacantes remotos provocar una denegación de servicio (parada del demonio) a través de una solicitud modificada. • http://www-01.ibm.com/support/docview.wss?uid=swg1PM71319 http://www.ibm.com/support/docview.wss?uid=swg21614265 https://exchange.xforce.ibmcloud.com/vulnerabilities/78047 •
CVE-2012-3304
https://notcve.org/view.php?id=CVE-2012-3304
The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors. La consola de administración de IBM WebSphere Application Server (WAS) v6.1 antes de v6.1.0.45, v7.0 antes de v7.0.0.25, v8.0 antes de v8.0.0.5, y v8.5 antes de v8.5.0.1 permite a los atacantes remotos secuestrar sesiones a través de vectores no especificados. • http://osvdb.org/85733 http://www-01.ibm.com/support/docview.wss?uid=swg1PM54356 http://www.ibm.com/support/docview.wss?uid=swg21611313 https://exchange.xforce.ibmcloud.com/vulnerabilities/77476 •
CVE-2012-3311
https://notcve.org/view.php?id=CVE-2012-3311
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors. IBM WebSphere Application Server (WAS) v6.1 anteriores a v6.1.0.45, 7.0 anteriores a v7.0.0.25, 8.0 anteriores a v8.0.0.5, y 8.5 anteriores a v8.5.0.1 en z/OS, en ciertas configuraciones que implican Federated Repositories para conexiones IIOP y Optimized Local Adapters, no hacen las comprobaciones CBIND, lo que permite a usuarios locales evitar las restricciones de acceso establecidas, y leer y modificar datos de aplicaciones, a través de vectores no específicos. • http://www-01.ibm.com/support/docview.wss?uid=swg1PM61388 http://www.ibm.com/support/docview.wss?uid=swg21611313 http://www.securityfocus.com/bid/55671 https://exchange.xforce.ibmcloud.com/vulnerabilities/77697 • CWE-264: Permissions, Privileges, and Access Controls •