Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.99% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 9/10/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554. | |
| Modificada | Media (5.3) | 0.93% | — | SAP Process Integration | 8/10/2019 | 17/6/2026 | SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check | |
| Modificada | Media (4.3) | 0.55% | — | SAP Netweaver Process Integration | 8/10/2019 | 17/6/2026 | SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Authorization Check. | |
| Modificada | Media (6.1) | 2.5% | — | Eclipse MojarraOracle Mojarra Javaserver FacesOracle Application Testing SuiteOracle Banking Enterprise Product Manufacturing+19 | 2/10/2019 | 17/6/2026 | faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled. | |
| Modificada | Media (6.5) | 3.8% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jOracle Application Performance Management+14 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys. | |
| Modificada | Media (6.5) | 2.5% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jOracle Application Performance Management+12 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys. | |
| Modificada | Media (6.5) | 1.7% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jMcafee Threat Intelligence Exchange Server+12 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key. | |
| Modificada | Media (4.3) | 0.70% | — | SAP Netweaver Process Integration | 10/9/2019 | 17/6/2026 | Under certain conditions SAP NetWeaver Process Integration Runtime Workbench – MESSAGING and SAP_XIAF (before versions 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Alta (7.5) | 16% | — | Apache Commons CompressFedoraproject FedoraOracle Banking PaymentsOracle Banking Platform+15 | 30/8/2019 | 17/6/2026 | The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress. | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Media (6.1) | 0.84% | — | SAP Netweaver Process Integration | 14/8/2019 | 17/6/2026 | Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and allows an attacker to execute malicious scripts in the url thereby resulting in Reflected Cross-Site Scripting (XSS) vulnerability | |
| Modificada | Alta (7.5) | 1.1% | — | Jenkins Codefresh Integration | 7/8/2019 | 17/6/2026 | Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM. | |
| Modificada | Crítica (9.8) | 16% | 💥 PoC | Softwareag QuartzOracle Apache Batik MapviewerOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+27 | 26/7/2019 | 17/6/2026 | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. | |
| Modificada | Media (6.1) | 1.6% | — | Pingidentity Agentless Integration KIT | 11/7/2019 | 17/6/2026 | XSS exists in Ping Identity Agentless Integration Kit before 1.5. | |
| Modificada | Alta (7.2) | 3.4% | — | SAP Netweaver Process Integration | 10/7/2019 | 17/6/2026 | ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights. An attacker could thereby impact the integrity and availability of the system. | |
| Modificada | Crítica (9.8) | 2.2% | — | Jetbrains Youtrack Integration | 3/7/2019 | 17/6/2026 | In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely. | |
| Modificada | Alta (8) | 2.6% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 19/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680. | |
| Modificada | Media (5.4) | 0.99% | — | IBM Maximo Asset ManagementIBM Control DeskIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 19/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949. | |
| Modificada | Media (4.8) | 0.62% | — | SAP Netweaver Process Integration | 14/6/2019 | 17/6/2026 | SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges to read and modify data from the victim’s browser, by injecting malicious scripts in certain… | |
| Modificada | Alta (7.5) | 1.4% | — | SAP Netweaver Process Integration | 12/6/2019 | 17/6/2026 | Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 and SAP_XIPCK 7.10 to 7.11, 7.20, 7.30) allows an attacker to access passwords used in FTP channels leading… | |
| Modificada | Media (5.3) | 1.1% | — | SAP Netweaver Process Integration | 12/6/2019 | 17/6/2026 | Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports or other technical data in the absence of… | |
| Modificada | Media (4.3) | 0.89% | — | SAP Netweaver Process Integration | 12/6/2019 | 17/6/2026 | Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in Clickjacking vulnerability. Successful… | |
| Modificada | Media (4.3) | 0.85% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565. | |
| Modificada | Baja (2.1) | 0.31% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311. | |
| Modificada | Media (6.5) | 0.77% | — | IBM Control DeskIBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+6 | 6/6/2019 | 17/6/2026 | IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554. |