Page 78 of 828 results (0.010 seconds)

CVSS: 4.9EPSS: 0%CPEs: 3EXPL: 0

IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages setting is enabled, allows remote authenticated users to write to pages via an XML injection attack. IBM WebSphere Portal 8.0.0 hasta 8.0.0.1 CF14 y 8.5.0 anteriores a CF04, cuando está habilitada la configuración Páginas Gestionadas, permite a usuarios remotos autenticados escribir en las páginas a través de un ataque de inyección XML. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI28699 http://www-01.ibm.com/support/docview.wss?uid=swg21692107 https://exchange.xforce.ibmcloud.com/vulnerabilities/98567 •

CVSS: 4.3EPSS: 0%CPEs: 17EXPL: 0

The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. El servicio Communications Enabled Applications (CEA) en IBM WebSphere Application Server 8.0.x anterior a 8.0.0.10 y 8.5.x anterior a 8.5.5.4 y Feature Pack for CEA 1.x anterior a 1.0.0.15 permite a atacantes remotos a leer archivos arbitrarios mediante una declaración de identidad XML externa junto con una referencia a una entidad, relacionado con el error XML External Entity (XXE). • http://www-01.ibm.com/support/docview.wss?uid=swg1PI25310 http://www-01.ibm.com/support/docview.wss?uid=swg1PI28632 http://www-01.ibm.com/support/docview.wss?uid=swg21690185 https://exchange.xforce.ibmcloud.com/vulnerabilities/97746 •

CVSS: 5.1EPSS: 0%CPEs: 7EXPL: 0

IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations. IBM WebSphere Application Server Liberty Profile 8.5.x anterior a 8.5.5.4 permite a atacantes remotos conseguir privilegios usando la combinación de restricciones de seguridad en los descriptores de despliegue de servlets y anotaciones ServletSecurity. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI29911 http://www-01.ibm.com/support/docview.wss?uid=swg21690185 http://www-01.ibm.com/support/docview.wss?uid=swg21963275 http://www.securityfocus.com/bid/71834 http://www.securitytracker.com/id/1033384 https://exchange.xforce.ibmcloud.com/vulnerabilities/99009 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.3EPSS: 0%CPEs: 48EXPL: 0

IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to conduct clickjacking attacks via a crafted web site. IBM WebSphere Application Server 7.x anterior a 7.0.0.37, 8.0.x anterior a 8.0.0.10 y 8.5.x anterior a 8.5.5.4 permiten a atacantes remotos llevar a cabo un ataque de clickjacking a través de un sitio web manipulado. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI27152 http://www-01.ibm.com/support/docview.wss?uid=swg21690185 https://exchange.xforce.ibmcloud.com/vulnerabilities/98486 • CWE-254: 7PK - Security Features •

CVSS: 4.3EPSS: 0%CPEs: 48EXPL: 0

Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en la funcionalidad de reescritura de URL en IBM WebSphere Application Server 7.x anterior a 7.0.0.37, 8.0.x anterior a 8.0.0.10 y 8.5.x anterior a 8.5.5.4 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI23819 http://www-01.ibm.com/support/docview.wss?uid=swg21690185 https://exchange.xforce.ibmcloud.com/vulnerabilities/97748 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •