Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
302 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | IBM Security Privileged Identity Manager Virtual Appliance | 26/9/2016 | 17/6/2026 | IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive information by leveraging a weak algorithm. | |
| Modificada | Media (6.8) | 1.1% | — | IBM Security Privileged Identity Manager Virtual Appliance | 26/9/2016 | 17/6/2026 | IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.34% | — | Vmware Identity ManagerVmware Vrealize Automation | 31/8/2016 | 17/6/2026 | VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Security Identity Manager Adapter | 15/7/2016 | 17/6/2026 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web site. | |
| Modificada | Alta (7.4) | 0.55% | — | IBM Security Identity Manager Adapter | 15/7/2016 | 17/6/2026 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allows remote attackers to hijack sessions by leveraging an unattended workstation. | |
| Modificada | Media (5.6) | 1.3% | — | IBM Security Identity Manager Adapter | 15/7/2016 | 17/6/2026 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records." | |
| Modificada | Media (6.2) | 0.36% | — | IBM Security Identity Manager Adapter | 15/7/2016 | 17/6/2026 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a configuration file or (2) examining a process. | |
| Modificada | Alta (7.3) | 1.2% | — | IBM Security Identity Manager Adapter | 15/7/2016 | 17/6/2026 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes it easier for remote attackers to obtain access by leveraging an attack against the password algorithm. | |
| Modificada | Alta (7.5) | 36% | — | HP Icewall Identity ManagerHP Icewall SSO Agent OptionApache TomcatDebian Linux+2 | 4/7/2016 | 7/10/2026 | The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string. | |
| Modificada | Media (6.1) | 1.4% | — | IBM Tivoli Federated Identity Manager | 18/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP16 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4.3) | 2.0% | — | IBM Tivoli Federated Identity Manager | 4/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to… | |
| Modificada | Baja (1.9) | 0.39% | — | IBM Security Identity Manager Active Directory AdapterIBM Tivoli Identity Manager Active Directory Adapter | 25/3/2015 | 17/6/2026 | The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows… | |
| Modificada | Media (6) | 0.47% | — | IBM Security Identity Manager | 29/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Modificada | Baja (2.1) | 0.58% | — | IBM Security Identity Manager | 18/11/2014 | 17/6/2026 | IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation. | |
| Modificada | Media (4.3) | 2.4% | — | IBM Security Identity Manager | 18/11/2014 | 17/6/2026 | IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session. | |
| Modificada | Media (4.3) | 2.4% | — | IBM Security Identity Manager | 18/11/2014 | 17/6/2026 | IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |
| Modificada | Media (5) | 2.7% | — | IBM Security Identity Manager | 18/11/2014 | 17/6/2026 | IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a crafted request. | |
| Modificada | Media (4.3) | 2.3% | — | IBM Security Identity Manager | 18/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 3.5% | — | IBM Security Identity Manager | 18/11/2014 | 17/6/2026 | Directory traversal vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 2.6% | — | IBM Tivoli Federated Identity Manager | 2/10/2014 | 17/6/2026 | Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0-TIV-TFIM-IF0015, 6.2.1 before 6.2.1-TIV-TFIM-IF0007, and 6.2.2 before 6.2.2-TIV-TFIM-IF0011 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.6) | 0.38% | — | Netiq Identity Manager | 21/6/2014 | 17/6/2026 | The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out Platform Services in Novell Identity Manager (aka IDM) 4.0.2 allows local users to execute arbitrary commands by leveraging eDirectory POSIX attribute changes to insert shell metacharacters. | |
| Modificada | Media (6) | 0.53% | — | IBM Security Identity ManagerIBM Tivoli Identity Manager | 8/6/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Modificada | Media (5.8) | 8.5% | 💥 Exploit | Oracle Identity Manager | 17/4/2014 | 17/6/2026 | Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin. | |
| Modificada | Media (4) | 1.2% | — | HP Icewall Identity ManagerHP Icewall SSO Password Reset Option | 5/4/2014 | 17/6/2026 | Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors. | |
| Modificada | Media (4.3) | 2.4% | — | Intel Expressway Cloud Access 360Mcafee Cloud Identity ManagerMcafee Cloud Single Sign ON | 18/3/2014 | 17/6/2026 | Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file containing a hash of the administrator password via unknown… |