Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8) | 1.4% | — | IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR Mobile SoftwareIBM Security Access Manager FOR WEB Software+1 | 21/6/2014 | 17/6/2026 | The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials. | |
| Modificada | Baja (3.3) | 0.36% | — | IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR WEB Appliance | 21/6/2014 | 17/6/2026 | The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0 with firmware 8.0.0.2 and 8.0.0.3 interprets the jct-nist-compliance parameter in the opposite of the intended manner, which makes it easier for remote attackers to obtain sensitive information by leveraging weak SSL encryption settings that… | |
| Modificada | Alta (7.1) | 3.1% | — | IBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB Appliance | 8/5/2014 | 17/6/2026 | The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages. | |
| Modificada | Media (6.9) | 0.32% | — | EMC RSA Access Manager | 1/5/2014 | 17/6/2026 | The runtime WS component in the server in EMC RSA Access Manager 6.1.3 before 6.1.3.39, 6.1.4 before 6.1.4.22, 6.2.0 before 6.2.0.11, and 6.2.1 before 6.2.1.03, when INFO logging is enabled, allows local users to discover cleartext passwords by reading log files. | |
| Modificada | Baja (3.5) | 0.85% | — | IBM Security Access Manager FOR Enterprise Single Sign-on | 23/12/2013 | 16/6/2026 | The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Security Access Manager FOR Enterprise Single Sign-on | 22/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form. | |
| Modificada | Media (4.3) | 0.93% | — | IBM Security Access Manager FOR Enterprise Single Sign-on | 22/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote attackers to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form. | |
| Modificada | Alta (7.8) | 3.2% | — | IBM Content Manager Ondemand FOR MultiplatformsIBM Global Security KITIBM Security Access Manager FOR WEB | 17/12/2013 | 17/6/2026 | IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of service via a crafted handshake during resumption of an SSLv2 session. | |
| Modificada | Alta (7.5) | 2.5% | — | HP Intelligent Management Center User Access Manager | 9/3/2013 | 16/6/2026 | Unspecified vulnerability in HP Intelligent Management Center (iMC) User Access Manager (UAM) before 5.2 E0402 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1643. | |
| Modificada | Media (6.8) | 0.68% | — | RSA Access Manager AgentRSA Access Manager Server | 5/7/2012 | 16/6/2026 | EMC RSA Access Manager Server 6.x before 6.1 SP4 and RSA Access Manager Agent do not properly validate session tokens after a logout, which might allow remote attackers to conduct replay attacks via unspecified vectors. | |
| Modificada | Alta (7.5) | 7.6% | 💥 Exploit | HP Protecttools Device Access Manager | 5/12/2011 | 16/6/2026 | The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a long SidString… | |
| Modificada | Alta (10) | 26% | — | HP Endpoint Admission DefenseHP Intelligent Management CenterHP User Access Manager | 11/7/2011 | 16/6/2026 | Stack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 before SP1 E0101P03 components in HP Intelligent Management Center (aka iNode Management Center) allows remote attackers to execute arbitrary code via a 0x0A0BF007 packet. | |
| Modificada | Media (5) | 1.7% | — | Oracle SUN Java System Access Manager Policy Agent | 20/4/2011 | 16/6/2026 | Unspecified vulnerability in the Oracle Sun Java System Access Manager Policy Agent 2.2 allows remote attackers to affect availability via unknown vectors related to Web Proxy Agent. | |
| Modificada | Alta (7.5) | 1.7% | — | RSA Access Manager Server | 16/3/2011 | 16/6/2026 | Unspecified vulnerability in EMC RSA Access Manager Server 5.5.x, 6.0.x, and 6.1.x allows remote attackers to access resources via unknown vectors. | |
| Modificada | Media (6.8) | 2.3% | — | Oracle OpenssoSUN Java System Access Manager | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (5) | 2.1% | — | IBM Tivoli Access Manager FOR E-business | 19/1/2011 | 16/6/2026 | Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 5.1 before 5.1.0.39-TIV-AWS-IF0040, 6.0 before 6.0.0.25-TIV-AWS-IF0026, 6.1.0 before 6.1.0.5-TIV-AWS-IF0006, and 6.1.1 before 6.1.1-TIV-AWS-FP0001 has unspecified impact and attack vectors. NOTE: this might overlap CVE-2010-4622. | |
| Modificada | Media (4) | 1.1% | — | IBM Tivoli Access Manager FOR E-business | 30/12/2010 | 16/6/2026 | WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 allows remote authenticated users to cause a denial of service (worker thread consumption) via shift-reload actions. | |
| Modificada | Media (5) | 2.9% | — | IBM Tivoli Access Manager FOR E-business | 30/12/2010 | 16/6/2026 | Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 on AIX allows remote attackers to read arbitrary files via a %uff0e%uff0e (encoded dot dot) in a URI. | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | IBM Tivoli Access Manager FOR E-business | 28/10/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the method parameter to (2) acl, (3) domain, (4) group, (5)… | |
| Modificada | Media (4.3) | 0.98% | — | RSA Access Manager Server | 9/9/2010 | 16/6/2026 | RSA Access Manager Server 5.5.3 before 5.5.3.172, 6.0.4 before 6.0.4.53, and 6.1 before 6.1.2.01 does not properly perform cache updates, which allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5.7) | 0.67% | — | RSA Access Manager Agent | 9/9/2010 | 16/6/2026 | Unspecified vulnerability in RSA Access Manager Agent 4.7.1 before 4.7.1.7, when RSA Adaptive Authentication Integration is enabled, allows remote attackers to bypass authentication and obtain sensitive information via unknown vectors. | |
| Modificada | Alta (10) | 6.4% | — | Novell Access Manager | 18/6/2010 | 16/6/2026 | Directory traversal vulnerability in the getEntry method in the PortalModuleInstallManager component in a servlet in nps.jar in the Administration Console (aka Access Management Console) in Novell Access Manager 3.1 before 3.1.2-281 on Windows allows remote attackers to create arbitrary files with any contents, and… | |
| Modificada | Media (4.3) | 1.0% | — | Novell Access Manager | 26/5/2010 | 16/6/2026 | The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions. | |
| Modificada | Media (4.3) | 1.2% | — | Novell Access Manager | 26/5/2010 | 16/6/2026 | Unspecified vulnerability in the Administration Console in Novell Access Manager before 3.1 SP1 allows attackers to access system files via unknown attack vectors. | |
| Modificada | Media (4.3) | 1.7% | — | SUN Java System Access ManagerSUN Java System WEB Server | 7/8/2009 | 16/6/2026 | The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors. |