Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.4% | — | IBM Websphere MQ | 26/6/2018 | 17/6/2026 | An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and 9.0.0 - 9.0.4) client connecting to a Queue Manager could cause a SIGSEGV in the Channel process amqrmppa. IBM X-Force ID: 137775. | |
| Modificada | Media (5.3) | 2.1% | — | IBM Websphere MQ | 15/6/2018 | 17/6/2026 | IBM WebSphere MQ 8.0 and 9.0, when configured to use a PAM module for authentication, could allow a user to cause a deadlock in the IBM MQ PAM code which could result in a denial of service. IBM X-Force ID: 138949. | |
| Modificada | Alta (7.8) | 0.38% | — | IBM Websphere Application Server | 24/5/2018 | 16/6/2026 | IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization. IBM X-Force ID: 84362. | |
| Modificada | Media (4.3) | 1.9% | — | IBM Websphere Application Server | 4/5/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could browse the file system. IBM X-Force ID: 134933. | |
| Modificada | Media (5.3) | 1.1% | — | IBM Websphere MQ | 23/4/2018 | 17/6/2026 | IBM WebSphere MQ 8.0 through 8.0.0.8 and 9.0 through 9.0.4 under special circumstances could allow an authenticated user to consume all resources due to a memory leak resulting in service loss. IBM X-Force ID: 136975. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Websphere Portal | 17/4/2018 | 17/6/2026 | IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139907. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Websphere MQ | 17/4/2018 | 17/6/2026 | An IBM WebSphere MQ 8.0.0.8, 9.0.0.2, and 9.0.4 Client connecting to a MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it. IBM X-Force ID: 137771. | |
| Modificada | Media (6.1) | 1.3% | — | IBM Websphere Portal | 11/4/2018 | 17/6/2026 | IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140918. | |
| Modificada | Media (5.3) | 0.92% | — | IBM Websphere MQ | 10/4/2018 | 17/6/2026 | IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-middle attack, related to duplication of message data in cleartext outside the protected payload. IBM X-Force ID: 103482. | |
| Modificada | Media (5.4) | 1.0% | — | IBM Business Process ManagerIBM Websphere Enterprise Service BUSIBM Websphere Process ServerIBM Business Process Manager Enterprise Service BUS | 30/3/2018 | 17/6/2026 | IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135. | |
| Modificada | Baja (3.3) | 0.38% | — | IBM Business Process ManagerIBM Business Process Manager Enterprise Service BUSIBM Websphere | 30/3/2018 | 17/6/2026 | IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856. | |
| Modificada | Media (6.5) | 2.0% | — | IBM Websphere MQ | 30/3/2018 | 17/6/2026 | A specially crafted message could cause a denial of service in IBM WebSphere MQ 9.0, 9.0.0.1, 9.0.0.2, 9.0.1, 9.0.2, 9.0.3, and 9.0.4 applications consuming messages that it needs to perform data conversion on. IBM X-Force ID: 135520. | |
| Modificada | Media (5.3) | 2.3% | — | IBM Websphere Application Server | 22/3/2018 | 17/6/2026 | IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 137031. | |
| Modificada | Media (5.4) | 0.93% | — | IBM Websphere Portal | 14/3/2018 | 17/6/2026 | IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139906. | |
| Modificada | Media (4.3) | 2.0% | — | IBM Websphere Application Server | 14/3/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could read files on the file system. IBM X-Force ID: 134931. | |
| Modificada | Media (6.1) | 1.3% | — | IBM Websphere Portal | 27/2/2018 | 17/6/2026 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138822. | |
| Modificada | Media (6.1) | 1.1% | — | IBM Websphere Portal | 9/2/2018 | 17/6/2026 | IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138437. | |
| Modificada | Media (6.1) | 0.98% | — | IBM Websphere Portal | 9/2/2018 | 17/6/2026 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136005. | |
| Modificada | Crítica (9.8) | 2.7% | — | IBM Websphere Application Server | 8/2/2018 | 16/6/2026 | The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to… | |
| Modificada | Alta (7.5) | 2.2% | — | IBM Websphere MQ | 7/2/2018 | 17/6/2026 | GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212. | |
| Modificada | Alta (8.8) | 2.8% | — | IBM Websphere Application Server | 30/1/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges. | |
| Modificada | Media (6.1) | 1.1% | — | IBM Websphere Portal | 11/1/2018 | 17/6/2026 | IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137158. | |
| Modificada | Alta (7.8) | 0.38% | — | IBM Websphere MQ | 9/1/2018 | 17/6/2026 | IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' user. IBM X-Force ID: 132953. | |
| Modificada | Baja (3.3) | 0.25% | — | IBM Websphere MQ | 4/1/2018 | 17/6/2026 | IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Websphere MQ | 2/1/2018 | 17/6/2026 | IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that could cause a channel process to cease processing further requests. IBM X-Force ID: 131547. |