Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.6% | — | IBM Websphere Application Server | 12/10/2018 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811. | |
| Modificada | Media (6.1) | 1.3% | — | IBM Websphere Portal | 12/10/2018 | 17/6/2026 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145108. | |
| Modificada | Media (6.1) | 1.4% | — | IBM Websphere Application Server | 3/10/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (6.1) | 1.4% | — | IBM Websphere Application Server | 3/10/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | |
| Modificada | Media (6.3) | 1.2% | — | IBM Websphere Portal | 1/10/2018 | 17/6/2026 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958. | |
| Modificada | Media (6.5) | 1.3% | — | IBM Websphere Portal | 1/10/2018 | 17/6/2026 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950. | |
| Modificada | Media (5.4) | 0.97% | — | IBM Websphere Portal | 27/9/2018 | 17/6/2026 | IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150096. | |
| Modificada | Media (6.1) | 1.5% | — | IBM Websphere Portal | 27/9/2018 | 17/6/2026 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site… | |
| Modificada | Media (6.1) | 1.3% | — | IBM Websphere Portal | 27/9/2018 | 17/6/2026 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147164. | |
| Modificada | Media (5.4) | 1.1% | — | IBM Websphere Portal | 27/9/2018 | 17/6/2026 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144886. | |
| Modificada | Alta (7.5) | 2.0% | — | IBM Websphere Application Server | 26/9/2018 | 17/6/2026 | IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455. | |
| Modificada | Media (5.9) | 2.4% | — | IBM Websphere Application Server | 14/9/2018 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to perform man-in-the-middle attacks. IBM X-Force ID: 147292. | |
| Modificada | Crítica (9.8) | 3.8% | — | IBM Websphere Application Server | 7/9/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024. | |
| Modificada | Media (5.6) | 2.2% | — | IBM Websphere Application Server | 6/9/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769. | |
| Modificada | Media (4.3) | 0.90% | — | IBM Websphere Commerce | 27/8/2018 | 17/6/2026 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenticated user to obtain sensitive information about another user. | |
| Modificada | Media (5.9) | 3.5% | — | IBM Websphere Application Server | 24/8/2018 | 17/6/2026 | IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is configured to permit access on non-secure… | |
| Modificada | Alta (7.5) | 1.1% | — | IBM Websphere MQ | 6/8/2018 | 17/6/2026 | IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name. IBM X-Force ID: 142888. | |
| Modificada | Media (4.3) | 2.0% | — | IBM Websphere MQ | 23/7/2018 | 17/6/2026 | IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely authenticated attacker to to send invalid or malformed headers that could cause messages to no longer be transmitted via the affected channel. IBM X-Force ID: 141339. | |
| Modificada | Alta (7.5) | 2.1% | — | IBM Websphere Cast Iron Cloud Integration | 11/7/2018 | 16/6/2026 | IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended access restrictions via unspecified vectors. IBM X-Force ID: 83868. | |
| Modificada | Alta (7.8) | 0.37% | — | IBM Websphere Portal | 11/7/2018 | 16/6/2026 | IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which allows local users to obtain sensitive information by reading the file. IBM X-Force ID: 83621. | |
| Modificada | Media (6.7) | 0.27% | — | IBM Websphere Application Server | 6/7/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346. | |
| Modificada | Media (4.4) | 0.36% | — | IBM Websphere MQ Managed File Transfer | 6/7/2018 | 17/6/2026 | IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042. | |
| Modificada | Alta (7.5) | 2.9% | — | IBM Websphere Application Server | 27/6/2018 | 17/6/2026 | IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890. | |
| Modificada | Media (5.9) | 1.1% | — | IBM Websphere MQ | 27/6/2018 | 17/6/2026 | IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142598. | |
| Modificada | Alta (7.5) | 2.9% | — | IBM Websphere Application Server | 26/6/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information. IBM X-Force ID: 144270. |