Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.98%—IBM Business Automation WorkflowIBM Business Process Manager8/4/201917/6/2026
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 154889.
ModificadaMedia (6.5)1.4%—IBM Business Automation WorkflowIBM Business Process Manager8/4/201917/6/2026
IBM Business Automation Workflow and Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 are vulnerable to a denial of service attack. An authenticated attacker might send a specially crafted request that exhausts server-side memory. IBM X-Force ID: 154774.
ModificadaMedia (5.3)1.8%—IBM Business Automation WorkflowIBM Business Process ManagerIBM Business Process Manager Enterprise Service BUSIBM Websphere Enterprise Service BUS8/4/201917/6/2026
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request. IBM X-Force ID: 152020.
ModificadaMedia (6.1)1.3%—IBM Business Automation WorkflowIBM Business Process ManagerIBM Websphere14/12/201817/6/2026
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150947.
ModificadaAlta (8.8)1.7%—IBM Business Automation WorkflowIBM Business Process Manager20/9/201817/6/2026
IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145109.
ModificadaMedia (5.4)1.0%—IBM Business Process ManagerIBM Websphere Enterprise Service BUSIBM Websphere Process ServerIBM Business Process Manager Enterprise Service BUS30/3/201817/6/2026
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135.
ModificadaMedia (5.4)1.0%—IBM Business Process Manager30/3/201817/6/2026
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136152.
ModificadaMedia (4.3)0.73%—IBM Business Process Manager30/3/201817/6/2026
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.
ModificadaMedia (4.3)1.4%—IBM Business Process ManagerIBM Business Process Manager Enterprise Service BUS30/3/201817/6/2026
IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive information about the application server. IBM X-Force ID: 136150.
ModificadaBaja (3.3)0.38%—IBM Business Process ManagerIBM Business Process Manager Enterprise Service BUSIBM Websphere30/3/201817/6/2026
IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.
ModificadaMedia (4.3)0.72%—IBM Business Process Manager15/3/201817/6/2026
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.
ModificadaAlta (8.8)0.97%—IBM Business Process Manager24/1/201817/6/2026
IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 136783.
ModificadaMedia (5.4)0.80%—IBM Business Process Manager20/12/201717/6/2026
IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692.
ModificadaMedia (6.5)1.8%—IBM Business Process Manager27/11/201717/6/2026
IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorization checks.
ModificadaAlta (8.8)1.5%—IBM Business Process Manager26/9/201717/6/2026
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.
ModificadaMedia (5.4)0.73%—IBM Business Process Manager26/9/201717/6/2026
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130410.
ModificadaMedia (5.4)0.73%—IBM Business Process Manager26/9/201717/6/2026
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409.
ModificadaAlta (8.1)2.0%—IBM Business Process Manager26/9/201717/6/2026
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 130156.
ModificadaMedia (5.4)0.73%—IBM Business Process Manager26/9/201717/6/2026
IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127478.
ModificadaMedia (5.4)0.73%—IBM Business Process Manager25/9/201717/6/2026
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477.
ModificadaBaja (2.5)0.21%—IBM Business Process Manager25/9/201717/6/2026
IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.
ModificadaMedia (6.5)1.00%—IBM Business Process ManagerIBM Websphere Application Server15/9/201717/6/2026
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.
ModificadaMedia (6.1)0.71%—IBM Business Process Manager28/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Business Process Manager Advanced 7.5.x before 7.5, 8.0.x before 8.0.1,…
ModificadaMedia (5.4)0.73%—IBM Business Process Manager8/6/201717/6/2026
IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaMedia (5.4)0.56%—IBM Business Process Manager22/5/201717/6/2026
IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that…
Orbitaley — Vulnerabilidades