Page 78 of 828 results (0.015 seconds)

CVSS: 4.3EPSS: 0%CPEs: 17EXPL: 0

Cross-site scripting (XSS) vulnerability in the Blog Portlet in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en el Portlet de Blog en IBM WebSphere Portal 6.1.0 hasta 6.1.0.6 CF27, 6.1.5 hasta 6.1.5.3 CF27, 7.0.0 hasta 7.0.0.2 CF29, 8.0.0 hasta 8.0.0.1 CF14 y 8.5.0 anteriores a CF04 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI29956 http://www-01.ibm.com/support/docview.wss?uid=swg21692107 https://exchange.xforce.ibmcloud.com/vulnerabilities/99150 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 17EXPL: 0

The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. El servicio Communications Enabled Applications (CEA) en IBM WebSphere Application Server 8.0.x anterior a 8.0.0.10 y 8.5.x anterior a 8.5.5.4 y Feature Pack for CEA 1.x anterior a 1.0.0.15 permite a atacantes remotos a leer archivos arbitrarios mediante una declaración de identidad XML externa junto con una referencia a una entidad, relacionado con el error XML External Entity (XXE). • http://www-01.ibm.com/support/docview.wss?uid=swg1PI25310 http://www-01.ibm.com/support/docview.wss?uid=swg1PI28632 http://www-01.ibm.com/support/docview.wss?uid=swg21690185 https://exchange.xforce.ibmcloud.com/vulnerabilities/97746 •

CVSS: 5.1EPSS: 0%CPEs: 7EXPL: 0

IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations. IBM WebSphere Application Server Liberty Profile 8.5.x anterior a 8.5.5.4 permite a atacantes remotos conseguir privilegios usando la combinación de restricciones de seguridad en los descriptores de despliegue de servlets y anotaciones ServletSecurity. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI29911 http://www-01.ibm.com/support/docview.wss?uid=swg21690185 http://www-01.ibm.com/support/docview.wss?uid=swg21963275 http://www.securityfocus.com/bid/71834 http://www.securitytracker.com/id/1033384 https://exchange.xforce.ibmcloud.com/vulnerabilities/99009 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.3EPSS: 0%CPEs: 48EXPL: 0

IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to conduct clickjacking attacks via a crafted web site. IBM WebSphere Application Server 7.x anterior a 7.0.0.37, 8.0.x anterior a 8.0.0.10 y 8.5.x anterior a 8.5.5.4 permiten a atacantes remotos llevar a cabo un ataque de clickjacking a través de un sitio web manipulado. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI27152 http://www-01.ibm.com/support/docview.wss?uid=swg21690185 https://exchange.xforce.ibmcloud.com/vulnerabilities/98486 • CWE-254: 7PK - Security Features •

CVSS: 4.3EPSS: 0%CPEs: 48EXPL: 0

Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en la funcionalidad de reescritura de URL en IBM WebSphere Application Server 7.x anterior a 7.0.0.37, 8.0.x anterior a 8.0.0.10 y 8.5.x anterior a 8.5.5.4 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI23819 http://www-01.ibm.com/support/docview.wss?uid=swg21690185 https://exchange.xforce.ibmcloud.com/vulnerabilities/97748 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •