Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.6% | — | IBM Websphere Portal | 27/12/2017 | 17/6/2026 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390. | |
| Modificada | Media (5.3) | 1.3% | — | IBM Websphere Portal | 20/12/2017 | 17/6/2026 | IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476. | |
| Modificada | Alta (7.1) | 0.29% | — | IBM Websphere MQ | 11/12/2017 | 17/6/2026 | IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a local user to crash the queue manager agent thread and expose some sensitive information. IBM X-Force ID: 126454. | |
| Modificada | Media (5.4) | 0.69% | — | IBM Websphere Portal | 11/12/2017 | 17/6/2026 | IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Media (6.5) | 1.4% | — | IBM Websphere MQ | 7/12/2017 | 17/6/2026 | IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow an authenticated user to insert messages with a corrupt RFH header into the channel which would cause it to restart. IBM X-Force ID: 127803. | |
| Modificada | Baja (3.7) | 0.98% | — | IBM Websphere MQ | 7/12/2017 | 17/6/2026 | IBM WebSphere MQ 8.0 and 9.0 could allow, under special circumstances, an unauthorized user to access an object which they should have been denied access. IBM X-Force ID: 126456. | |
| Modificada | Media (4.3) | 0.96% | — | IBM Websphere Commerce | 27/11/2017 | 17/6/2026 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an authenticated attacker to obtain information such as user personal data. IBM X-Force ID: 128622. | |
| Modificada | Media (4.3) | 0.94% | — | IBM Websphere MQ | 27/11/2017 | 17/6/2026 | IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a shared memory leak by MQ applications using dynamic queues, which can lead to lack of resources for other MQ applications. IBM X-Force ID: 125144. | |
| Modificada | Media (6.1) | 1.7% | — | IBM Websphere Application Server | 10/10/2017 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks,… | |
| Modificada | Media (5.3) | 1.2% | — | IBM Integration BUSIBM Websphere Message Broker | 4/10/2017 | 17/6/2026 | IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341. | |
| Modificada | Alta (7.5) | 1.8% | — | IBM Websphere Commerce | 3/10/2017 | 17/6/2026 | IBM WebSphere Commerce 7.0 and 8.0 contains an unspecified vulnerability in Marketing ESpot's that could cause a denial of service. IBM X-Force ID: 131779. | |
| Modificada | Alta (7.5) | 2.9% | — | IBM Websphere Portal | 28/9/2017 | 17/6/2026 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 132117. | |
| Modificada | Media (6.5) | 2.3% | 💥 PoC | IBM Websphere MQ | 25/9/2017 | 17/6/2026 | IBM WebSphere MQ 8.0 could allow an authenticated user to cause a premature termination of a client application thread which could potentially cause denial of service. IBM X-Force ID: 123914. | |
| Modificada | Media (6.5) | 1.00% | — | IBM Business Process ManagerIBM Websphere Application Server | 15/9/2017 | 17/6/2026 | IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL. | |
| Modificada | Media (6.1) | 1.1% | — | IBM Websphere Portal | 7/9/2017 | 17/6/2026 | IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123558. | |
| Modificada | Media (5.9) | 2.0% | — | IBM Websphere Application Server | 18/8/2017 | 17/6/2026 | IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web services security bindings settings. IBM X-Force ID: 129576. | |
| Modificada | Media (6.5) | 0.94% | — | IBM Websphere Application Server | 3/8/2017 | 17/6/2026 | IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579. | |
| Modificada | Alta (7.5) | 1.9% | — | IBM Websphere MQ Internet Pass-thru | 2/8/2017 | 17/6/2026 | IBM WebSphere MQ Internet Pass-Thru 2.0 and 2.1 could allow n attacker to cause the MQIPT to stop responding due to an incorrectly configured security policy. IBM X-Force ID: 121156. | |
| Modificada | Media (6.1) | 1.3% | — | IBM Websphere Portal | 31/7/2017 | 17/6/2026 | IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | |
| Modificada | Alta (7.1) | 0.37% | — | IBM Websphere Application Server | 24/7/2017 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153. | |
| Modificada | Media (5.4) | 1.0% | — | IBM Websphere Application Server | 24/7/2017 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127151. | |
| Modificada | Baja (3.3) | 0.38% | — | IBM Websphere Application Server | 21/7/2017 | 17/6/2026 | IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152. | |
| Modificada | Media (6.5) | 1.7% | — | IBM Websphere MQ | 12/7/2017 | 17/6/2026 | IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to remain in a running state but not process messages. IBM X-Force ID: 125146. | |
| Modificada | Media (6.1) | 0.99% | — | IBM Websphere Commerce | 10/7/2017 | 17/6/2026 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed… | |
| Modificada | Alta (8.1) | 1.5% | — | IBM Websphere MQ | 10/7/2017 | 17/6/2026 | IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245. |