Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
302 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.7% | — | IBM Tivoli Identity Manager | 5/7/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. NOTE: it was later reported that 4.6.0 is also affected by the… | |
| Modificada | Media (6.4) | 2.6% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object. | |
| Modificada | Alta (9) | 3.7% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapters." | |
| Modificada | Alta (9) | 3.4% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and… | |
| Modificada | Media (4.3) | 2.0% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661. | |
| Modificada | Media (4.3) | 2.0% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033. | |
| Modificada | Media (4.3) | 2.0% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 19660, and 19683. | |
| Modificada | Media (4) | 1.8% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact. | |
| Modificada | Media (6.5) | 2.5% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrator's password. | |
| Modificada | Media (5) | 2.3% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. | |
| Modificada | Media (5) | 2.5% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. | |
| Modificada | Media (5) | 2.5% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of support for relative URLs. | |
| Modificada | Media (4.3) | 2.0% | — | SUN Java System Identity Manager | 18/11/2008 | 16/6/2026 | Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "frame injection." | |
| Modificada | Media (6.4) | 2.6% | — | SUN Java System Identity Manager | 18/11/2008 | 16/6/2026 | Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Alta (7.8) | 4.1% | — | SUN Java System Identity Manager | 18/11/2008 | 16/6/2026 | Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter. | |
| Modificada | Media (6.8) | 3.1% | 💥 Exploit | SUN Java System Identity Manager | 18/11/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp. | |
| Modificada | Media (4.3) | 1.9% | — | SUN Java System Identity Manager | 18/11/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Novell Identity Manager Roles Based Provisioning ModuleNovell User Application | 14/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (5.8) | 2.7% | — | SUN Java System Identity Manager | 11/1/2008 | 16/6/2026 | Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter. | |
| Modificada | Media (4.3) | 5.7% | 💥 Exploit | SUN Java System Identity Manager | 11/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3)… | |
| Modificada | Media (4.3) | 5.8% | 💥 Exploit | SUN Java System Identity Manager | 11/1/2008 | 16/6/2026 | /idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection." | |
| Modificada | Media (5) | 1.8% | — | Novell Identity Manager | 4/1/2008 | 16/6/2026 | The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus… | |
| Modificada | Baja (2.1) | 0.40% | — | Netiq Identity ManagerNovell Client Login Extension (cle) | 25/8/2007 | 16/6/2026 | The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file. | |
| Modificada | Baja (2.7) | 0.50% | — | IBM Tivoli Identity Manager | 18/12/2006 | 16/6/2026 | The Java Key Store (JKS) for WebSphere Application Server (WAS) for IBM Tivoli Identity Manager (ITIM) 4.6 places the JKS password in a -Djavax.net.ssl.trustStorePassword command line argument, which allows local users to obtain the password by listing the process or using other methods. | |
| Modificada | Alta (7.2) | 0.51% | — | Netiq Identity Manager | 14/9/2006 | 16/6/2026 | The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors involving certain environment variables and "code injection." |