Page 5 of 433 results (0.008 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

25 Jan 2022 — IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875. IBM WebSphere Application Server - Liberty versiones 17.0.0.3 hasta 22.0.0.1 podría permitir a un atacante remoto autenticado conducir una inyección LDAP. Usando una petición especialmente dis... • https://exchange.xforce.ibmcloud.com/vulnerabilities/213875 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVSS: 6.5EPSS: 0%CPEs: 9EXPL: 0

19 Jan 2022 — IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224. IBM WebSphere Application Server Liberty versiones 21.0.0.10 hasta 21.0.0.12, podría proporcionar una seguridad más débil de lo esperado. Un atacante remoto podría explotar esta debilidad para obtener información confidencial y conseguir acces... • https://exchange.xforce.ibmcloud.com/vulnerabilities/217224 •

CVSS: 7.5EPSS: 0%CPEs: 11EXPL: 0

09 Dec 2021 — IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405. IBM WebSphere Application Server versiones 7.0, 8.0, 8.5 y 9.0, es vulnerable a una denegación de servicio, causada por el envío de una petición especialmente diseñada. Un atacante remoto podría aprovechar esta vulnerabilidad para causa... • https://exchange.xforce.ibmcloud.com/vulnerabilities/211405 •

CVSS: 5.3EPSS: 0%CPEs: 5EXPL: 0

16 Sep 2021 — IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202. IBM WebSphere Application Server versiones 7.0, 8.0, 8.5, 9.0 y Liberty versiones 17.0.0.3 hasta 21.0.0.9, podrían permitir a un usuario remoto enumerar nombres de usuario debido a una diferencia de respuestas de intentos de inicio de sesión válidos y no válidos. IBM X-Force I... • https://exchange.xforce.ibmcloud.com/vulnerabilities/205202 • CWE-307: Improper Restriction of Excessive Authentication Attempts •

CVSS: 8.8EPSS: 0%CPEs: 11EXPL: 0

30 Jul 2021 — IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300. IBM WebSphere Application Server versiones 7.0, 8.0, 8.5 y 9.0 podría permitir a un usuario remoto alcanzar privilegios elevados en el sistema. IBM X-Force ID: 201300 • https://exchange.xforce.ibmcloud.com/vulnerabilities/201300 •

CVSS: 8.8EPSS: 0%CPEs: 11EXPL: 0

11 Jun 2021 — IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006. IBM WebSphere Application Server versiones 7.0, 8.0, 8.5 y 9.0 es suceptible a una vulnerabilidad de escalada de privilegios cuando se usa el SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006 • https://exchange.xforce.ibmcloud.com/vulnerabilities/202006 •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0

07 Jun 2021 — IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to read and delete arbitrary files on the system. IBM X-Force ID: 198435. IBM WebSphere Application Server Network Deployment versiones 8.5 y 9.0, podría permitir a un atacante remoto autenticado saltar directorios. Un atacante podría enviar una petición de URL especialmente diseñada c... • https://exchange.xforce.ibmcloud.com/vulnerabilities/198435 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 8.2EPSS: 0%CPEs: 4EXPL: 0

26 May 2021 — IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793. IBM WebSphere Application Server versiones 8.0, 8.5, 9.0 y Liberty Java Batch es vulnerable a un ataque de tipo XML External Entity Injection (XXE) cuando procesa datos XML. Un atacante remoto podría explotar es... • https://exchange.xforce.ibmcloud.com/vulnerabilities/197793 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 8.2EPSS: 0%CPEs: 4EXPL: 0

21 Apr 2021 — IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649. IBM WebSphere Application Server versiones 7.0, 8.0, 8.5 y 9.0, es vulnerable a un ataque de tipo XML External Entity Injection (XXE) cuando se procesan datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exp... • https://exchange.xforce.ibmcloud.com/vulnerabilities/196649 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 8.2EPSS: 0%CPEs: 3EXPL: 0

20 Apr 2021 — IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648. IBM WebSphere Application Server versiones 8.0, 8.5 y 9.0, es vulnerable a un ataque de inyección de XML External Entity Injection (XXE) cuando se procesan datos XML. Un atacante remoto podría explotar esta vulnerabilidad para expon... • https://exchange.xforce.ibmcloud.com/vulnerabilities/196648 • CWE-611: Improper Restriction of XML External Entity Reference •