Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.7) | 0.29% | — | IBM Websphere MQ | 10/7/2017 | 17/6/2026 | IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to obtain sensitive information from WebSphere Application Server traces including user credentials. IBM X-Force ID: 125145. | |
| Modificada | Media (6.5) | 1.4% | — | IBM Websphere MQ | 6/7/2017 | 17/6/2026 | IBM WebSphere MQ 9.0.2 could allow an authenticated user to potentially cause a denial of service by saving an incorrect channel status inquiry. IBM X-Force ID: 124354 | |
| Modificada | Baja (2.5) | 0.28% | — | IBM Websphere Message BrokerIBM Integration BUS | 5/7/2017 | 17/6/2026 | IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033. | |
| Modificada | Media (5.5) | 0.32% | — | IBM Websphere Message BrokerIBM Integration BUS | 5/7/2017 | 17/6/2026 | IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777. | |
| Modificada | Media (6.1) | 1.1% | — | IBM Websphere Portal | 5/7/2017 | 17/6/2026 | IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857 | |
| Modificada | Media (5.3) | 1.1% | — | IBM Websphere MQ | 21/6/2017 | 17/6/2026 | IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a denial of service to the MQXR channel when trace is enabled. IBM X-Force ID: 121155. | |
| Modificada | Media (5.3) | 2.3% | — | IBM Websphere Application Server | 8/6/2017 | 17/6/2026 | IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information. | |
| Modificada | Media (5.5) | 0.32% | — | IBM Websphere MQ | 7/6/2017 | 17/6/2026 | IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926. | |
| Modificada | Alta (8.1) | 1.9% | — | IBM Websphere Application Server | 10/5/2017 | 17/6/2026 | IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549. | |
| Modificada | Alta (8.8) | 1.1% | — | IBM Websphere Portal | 5/5/2017 | 17/6/2026 | IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would… | |
| Modificada | Alta (8.6) | 1.6% | — | IBM Websphere Cast Iron Solution | 5/5/2017 | 17/6/2026 | IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By… | |
| Modificada | Alta (8.6) | 1.4% | — | IBM Websphere Cast Iron Solution | 5/5/2017 | 17/6/2026 | IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID:… | |
| Modificada | Alta (8.8) | 0.88% | — | IBM Websphere Application Server | 28/4/2017 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669. | |
| Modificada | Media (5.3) | 0.32% | — | IBM Websphere Commerce | 26/4/2017 | 17/6/2026 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230. | |
| Modificada | Media (6.1) | 0.96% | — | IBM Websphere Portal | 27/3/2017 | 17/6/2026 | IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000152. | |
| Modificada | Alta (8.1) | 2.2% | — | IBM Websphere Application Server | 20/3/2017 | 17/6/2026 | IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated privileges on the system. IBM Reference #: 1999293. | |
| Modificada | Alta (8.6) | 1.9% | — | IBM Websphere MQ | 20/3/2017 | 17/6/2026 | IBM WebSphere MQ 8.0.0.6 does not properly terminate channel agents when they are no longer needed, which could allow a user to cause a denial of service through resource exhaustion. IBM Reference #: 1999672. | |
| Modificada | Media (5.1) | 0.31% | — | IBM Websphere Commerce | 8/3/2017 | 17/6/2026 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408. | |
| Modificada | Media (6.1) | 0.53% | — | IBM Business Process ManagerIBM Websphere | 7/3/2017 | 17/6/2026 | IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and… | |
| Modificada | Media (6.5) | 0.90% | — | IBM Websphere MQ | 7/3/2017 | 17/6/2026 | IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault which would result in the box having to be rebooted to resume normal operations. IBM Reference #: 1998663. | |
| Modificada | Baja (3.1) | 0.81% | — | IBM Websphere MQ | 24/2/2017 | 17/6/2026 | IBM WebSphere MQ 8.0 could allow an authenticated user with authority to create a cluster object to cause a denial of service to MQ clustering. IBM Reference #: 1998647. | |
| Modificada | Media (6.5) | 1.0% | — | IBM Websphere MQ | 22/2/2017 | 17/6/2026 | IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests. IBM Reference #: 1998648. | |
| Modificada | Media (6.5) | 0.84% | — | IBM Websphere MQ | 22/2/2017 | 17/6/2026 | IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. IBM Reference #: 1998649. | |
| Modificada | Media (5.9) | 0.83% | — | IBM Websphere MQ | 22/2/2017 | 17/6/2026 | Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man in the middle techniques. | |
| Modificada | Media (6.5) | 0.91% | — | IBM Websphere MQ | 22/2/2017 | 17/6/2026 | IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling. IBM Reference #: 1998661. |