Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Netiq Access Manager26/1/201817/6/2026
A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access Manager versions 4.3 and 4.4 as well as the Administrative console.
ModificadaCrítica (9.8)35%—Netiq Access Manager20/1/201817/6/2026
In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system.
ModificadaMedia (5.9)1.6%—Oracle Access Manager18/1/201817/6/2026
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). The supported version that is affected is 11.1.2.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Access Manager. Successful…
ModificadaBaja (3.3)0.39%—IBM Security Access Manager 9.0 Firmware11/1/201817/6/2026
IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613.
ModificadaMedia (6.1)1.0%—IBM Security Access Manager FOR WEB FirmwareIBM Security Access Manager FOR MobileIBM Security Access Manager Firmware10/1/201817/6/2026
IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious…
ModificadaMedia (6.1)1.1%—IBM Security Access Manager 9.0 Firmware10/1/201817/6/2026
IBM Security Access Manager Appliance 9.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130675.
ModificadaMedia (4.2)0.58%—IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR MobileIBM Security Access Manager 9.0 Firmware10/1/201817/6/2026
IBM Security Access Manager Appliance 8.0.0 and 9.0.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 128378.
ModificadaAlta (8.1)1.4%—IBM Security Access Manager 9.0 Firmware13/11/201717/6/2026
IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128612.
ModificadaAlta (8.8)2.9%—IBM Security Access Manager 9.0 Firmware13/11/201717/6/2026
IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 128372.
ModificadaAlta (7.5)40%💥 PoCOpensslDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4113/11/201717/6/2026
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections…
ModificadaMedia (5.3)1.9%—Oracle Access Manager19/10/201717/6/2026
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks…
ModificadaMedia (6.1)1.2%—IBM Tivoli Access Manager FOR E-businessIBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR WEB+229/8/201717/6/2026
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.
ModificadaMedia (4.3)0.94%—IBM Security Access Manager 9.0 Firmware7/6/201717/6/2026
IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.
ModificadaMedia (6.5)0.76%—IBM Security Access Manager 9.0 Firmware7/6/201717/6/2026
IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.
ModificadaMedia (6.1)0.68%—Netiq Access Manager24/4/201717/6/2026
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
ModificadaMedia (6.1)0.67%—Netiq Access Manager20/4/201717/6/2026
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.
ModificadaBaja (3.1)0.67%—Netiq Access Manager20/4/201717/6/2026
NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.
ModificadaAlta (8.8)0.50%—Netiq Access Manager23/3/201717/6/2026
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
ModificadaCrítica (9.8)1.5%—Netiq Access Manager23/3/201717/6/2026
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.
ModificadaMedia (6.1)0.64%—Netiq Access Manager23/3/201717/6/2026
Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack user sessions: nps/servlet/frameservice, nps/servlet/webacc, roma/admin/cntl,…
ModificadaMedia (6.5)0.50%—Netiq Access Manager23/3/201717/6/2026
NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high encryption" setting.
ModificadaAlta (7.5)1.1%—Netiq Access Manager23/3/201717/6/2026
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.
ModificadaAlta (7.5)1.1%—Netiq Access Manager23/3/201717/6/2026
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the original requester.
ModificadaMedia (6.1)0.71%—Netiq Access Manager23/3/201717/6/2026
An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 could be used to trigger XSS and leak authentication credentials.
ModificadaAlta (8.8)1.1%—Netiq Access Manager23/3/201717/6/2026
The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users.
Orbitaley — Vulnerabilidades