Page 7 of 37 results (0.012 seconds)

CVSS: 3.3EPSS: 0%CPEs: 52EXPL: 0

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors. IBM WebSphere Application Server (WAS) v6.1 anteriores a v6.1.0.45, 7.0 anteriores a v7.0.0.25, 8.0 anteriores a v8.0.0.5, y 8.5 anteriores a v8.5.0.1 en z/OS, en ciertas configuraciones que implican Federated Repositories para conexiones IIOP y Optimized Local Adapters, no hacen las comprobaciones CBIND, lo que permite a usuarios locales evitar las restricciones de acceso establecidas, y leer y modificar datos de aplicaciones, a través de vectores no específicos. • http://www-01.ibm.com/support/docview.wss?uid=swg1PM61388 http://www.ibm.com/support/docview.wss?uid=swg21611313 http://www.securityfocus.com/bid/55671 https://exchange.xforce.ibmcloud.com/vulnerabilities/77697 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent directory browsing, which allows remote attackers to obtain sensitive information via HTTP requests. El componente de servidor web en Consolidation and Analysis Engine (CAE) Server en DB2 Query Monitor en IBM DB2 Tools v2.3.0 para z/OS no impide la exploración de directorios, lo que permite a atacantes remotos obtener información sensible a través de peticiones HTTP. • http://secunia.com/advisories/46487 http://www.ibm.com/support/docview.wss?uid=swg1PM41190 http://www.securitytracker.com/id?1026278 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 6.8EPSS: 1%CPEs: 100EXPL: 0

IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registry or Federated Repository with RACF adapter is used, allows remote attackers to obtain unspecified application access via unknown vectors. IBM WebSphere Application Server (WAS) v6.0.x hasta v6.0.2.43, v6.1.x anterior a v6.1.0.37, y v7.0.x anterior a v7.0.0.17 sobre z/OS, cuando un usuario registrado en Locla OS o Federated Repository con adaptador RACF está usada, permite a atacantes remotos obtener acceso a aplicaciones no especificadas a través de vectores desconocidos. • http://secunia.com/advisories/43965 http://www-01.ibm.com/support/docview.wss?uid=swg21473989 http://www.ibm.com/support/docview.wss?uid=swg1PM35478 http://www.ibm.com/support/docview.wss?uid=swg1PM35480 http://www.ibm.com/support/docview.wss?uid=swg1PM35545 http://www.ibm.com/support/docview.wss? • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.3EPSS: 1%CPEs: 55EXPL: 0

mod_ibm_ssl in IBM HTTP Server 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11, as used in IBM WebSphere Application Server (WAS) on z/OS, does not properly handle a large HTTP request body in uploading over SSL, which might allow remote attackers to cause a denial of service (daemon fail) via an upload. mod_ibm_ssl en IBM HTTP Server v6.0 anteriores a v6.0.2.43, v6.1 anteriores a v6.1.0.33, y v7.0 anteriores a v7.0.0.11, como las utilizadas en IBM WebSphere Application Server (WAS) en z/OS, no gestionan de forma adecuada los body largos en las peticiones HTTP en las subidas sobre SSL, lo que podría permitir a atacantes remotos provocar una denegación de servicio (fallo del demonio) a través de una subida. • http://secunia.com/advisories/40096 http://www-01.ibm.com/support/docview.wss?uid=swg1PM10270 http://www-01.ibm.com/support/docview.wss?uid=swg1PM15830 http://www.osvdb.org/65439 http://www.vupen.com/english/advisories/2010/1411 • CWE-20: Improper Input Validation •

CVSS: 1.9EPSS: 0%CPEs: 46EXPL: 0

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log. IBM WebSphere Application Server (WAS) v6.1.x antes de v6.1.0.31 y v7.0.x antes de v7.0.0.11, cuando estan habilitados la autenticación Basic y las trazas SIP (esto es, los logs para SIP estan completamente habilitados), almacena en los logs la totalidad de todos los mensajes SIP entrantes y salientes, lo que permite a usuarios locales obtener información sensible mediante la lectura del fichero de log. • http://secunia.com/advisories/39628 http://secunia.com/advisories/40096 http://www-01.ibm.com/support/docview.wss?uid=swg1PM08892 http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247 http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829 http://www.osvdb.org/65437 http://www.vupen.com/english/advisories/2010/1411 https://exchange.xforce.ibmcloud.com/vulnerabilities/58324 • CWE-310: Cryptographic Issues •