
CVE-2020-4575
https://notcve.org/view.php?id=CVE-2020-4575
27 Aug 2020 — IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured. IBM WebSphere Application Server ND versiones 8.5 y 9.0, e IBM WebSphere Virtual Enterprise versiones 7.0 y 8.0, son vulnerables a un ataque de tipo cross-site scripting cuando High Availability Deployment Manager es configurado • https://exchange.xforce.ibmcloud.com/vulnerabilities/184363 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-4448 – IBM WebSphere UploadFileArgument Directory Traversal Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-4448
05 Jun 2020 — IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228. IBM WebSphere Application Server Network Deployment versiones 7.0, 8.0, 8.5 y 9.0, podría permitir a un atacante remoto ejecutar código arbitrario en el sistema con una secuencia de objetos serializados especialmente diseñada de fuentes no confiables. ID de IBM X... • https://exchange.xforce.ibmcloud.com/vulnerabilities/181228 • CWE-502: Deserialization of Untrusted Data •

CVE-2019-4505
https://notcve.org/view.php?id=CVE-2019-4505
20 Sep 2019 — IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL. This can lead the attacker to view any file in a certain directory. IBM X-Force ID: 164364. IBM WebSphere Application Server versiones 7.0, 8.0, 8.5 y 9.0, Network Deployment podría permitir a un atacante remoto obtener información confidencial, causado mediante el envío de una URL especialmente diseñada. Esto puede conllevar al ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/164364 •

CVE-2019-4030
https://notcve.org/view.php?id=CVE-2019-4030
06 Mar 2019 — IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155946. IBM WebSphere Application Server, en sus versiones 8.5 y 9.0, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usua... • http://www.ibm.com/support/docview.wss?uid=ibm10869406 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-1932
https://notcve.org/view.php?id=CVE-2015-1932
22 Aug 2015 — IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header. Vulnerabilidad en IBM WebSpher Application Server en 7.x en versiones anteriores a 7.0.0.39, 8.0.x en versiones anteriores a 8.0.0.11, 8.5.x en versiones anteriores a 8.5.5.7 y WebSphere Virtual Enterprise en versiones anteriores a... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI38403 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-1946
https://notcve.org/view.php?id=CVE-2015-1946
14 Jul 2015 — IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors. WebSphere Application Server (WAS) 8.5 anteriores a 8.5.5.6 y WebSphere Virtual Enterprise 7.0 anteriores a 7.0.0.6 para WebSphere Application Server (WAS) 7.0 y 8.0, no tienen los roles de usuarios correctamente implementados lo que permit... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI35180 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-6323
https://notcve.org/view.php?id=CVE-2013-6323
01 May 2014 — Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en la consola de administración en IBM WebSphere Application Server (WAS) 7.x anterior a 7.0.0.33, 8.x anterior a 8.0.0.9 y 8.5.x anterior a 8.5.5.2 y WebSphere Virt... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI04777 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-5425
https://notcve.org/view.php?id=CVE-2013-5425
16 Nov 2013 — Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en la Administration Console de IBM WebSphere Virtual Enterprise 6.1 anterior a la versión 6.1.1.6 y 7.0 anterior a 7.0.0.4 permite a usuarios remotos autenticados inyectar script web o HTML arbitrario a través de una URL diseñada. • http://www-01.ibm.com/support/docview.wss?uid=swg1PM93828 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •