Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.0% | — | IBM Websphere Portal | 29/10/2015 | 17/6/2026 | IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted request. | |
| Modificada | Media (5) | 2.1% | — | IBM Websphere Portal | 28/10/2015 | 17/6/2026 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by configuration… | |
| Modificada | Baja (3.2) | 0.33% | — | IBM Websphere Message BrokerIBM Integration BUS | 26/10/2015 | 17/6/2026 | IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 1.4% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to hijack web sessions via a session identifier. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL. | |
| Modificada | Baja (2.1) | 0.50% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation. | |
| Modificada | Media (6) | 0.54% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | |
| Modificada | Media (4) | 1.6% | — | IBM Websphere Commerce | 14/9/2015 | 17/6/2026 | Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain sensitive personal information via unknown vectors. | |
| Modificada | Alta (7.8) | 2.7% | — | IBM Websphere Portal | 14/9/2015 | 17/6/2026 | IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request. | |
| Modificada | Media (5) | 2.4% | — | IBM Websphere MQ | 14/9/2015 | 17/6/2026 | IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection string in an MQI call. | |
| Modificada | Baja (3.5) | 0.87% | — | IBM Integration BUSIBM Websphere Message Broker | 23/8/2015 | 17/6/2026 | IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | IBM Websphere Application Server | 22/8/2015 | 17/6/2026 | IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | IBM Websphere Virtual EnterpriseIBM Websphere Application Server | 22/8/2015 | 17/6/2026 | IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header. | |
| Modificada | Media (5) | 1.2% | — | IBM Websphere Extreme Scale | 3/8/2015 | 17/6/2026 | Unspecified vulnerability in IBM WebSphere eXtreme Scale 8.6 through 8.6.0.8 allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Alta (7.8) | 2.1% | — | IBM Websphere MQ Light | 3/8/2015 | 17/6/2026 | IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1958. | |
| Modificada | Baja (2.1) | 0.33% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 3/8/2015 | 17/6/2026 | The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and attaching it elsewhere. | |
| Modificada | Alta (7.8) | 1.5% | — | IBM Websphere MQ Light | 3/8/2015 | 17/6/2026 | IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1987. | |
| Modificada | Alta (7.8) | 1.5% | — | IBM Websphere MQ Light | 3/8/2015 | 17/6/2026 | IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1958 and CVE-2015-1987. | |
| Modificada | Alta (7.8) | 1.5% | — | IBM Websphere MQ Light | 3/8/2015 | 17/6/2026 | IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a crafted byte sequence in authentication data. | |
| Modificada | Media (4.4) | 0.35% | — | IBM Websphere Application ServerIBM Websphere Virtual Enterprise | 14/7/2015 | 17/6/2026 | IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (6) | 1.7% | — | IBM Websphere Application Server | 14/7/2015 | 17/6/2026 | The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter. | |
| Modificada | Media (6.8) | 2.1% | — | IBM Websphere Application Server | 14/7/2015 | 17/6/2026 | The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified… |