Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.22% | — | IBM Infosphere Information ServerIBM Infosphere Information Server ON Cloud | 1/6/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user. | |
| Analizada | Media (4.3) | 0.28% | — | IBM Infosphere Information ServerIBM Infosphere Information Server ON Cloud | 15/5/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing. | |
| Analizada | Baja (3.7) | 0.18% | — | IBM Infosphere Information Server | 23/4/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques. | |
| Analizada | Media (4.3) | 0.30% | — | IBM Infosphere Information Server | 23/4/2025 | 17/6/2026 | IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system. | |
| Analizada | Media (6.3) | 0.25% | — | IBM Infosphere Information Server | 23/4/2025 | 17/6/2026 | IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (5.3) | 0.35% | — | IBM Infosphere Information Server | 29/3/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Alta (7.5) | 0.30% | — | IBM Infosphere Information Server | 29/3/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product. | |
| Analizada | Media (6.5) | 0.31% | — | IBM Infosphere Information Server | 29/3/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy. | |
| Analizada | Media (6.5) | 0.27% | — | IBM Infosphere Information Server | 29/3/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions. | |
| Analizada | Alta (7.8) | 0.14% | — | IBM Infosphere Information Server | 19/3/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions. | |
| Analizada | Media (4.3) | 0.38% | — | IBM Infosphere Information Server | 24/1/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid in further attacks against the system. | |
| Analizada | Alta (7.5) | 0.61% | — | IBM Infosphere Information Server | 17/1/2025 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Analizada | Media (5.2) | 0.27% | — | IBM Infosphere Information Server | 19/12/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. | |
| Analizada | Media (6.5) | 0.54% | — | IBM Infosphere Information Server | 12/12/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation. | |
| Analizada | Media (4.3) | 0.30% | — | IBM Infosphere Information Server | 11/12/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. | |
| Analizada | Media (6.5) | 0.34% | — | IBM Infosphere Information Server | 11/12/2024 | 17/6/2026 | IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. | |
| Aplazada | Crítica (9.4) | 0.61% | — | Siemens Simatic BatchAISiemens Simatic Information ServerAISiemens Simatic PCS 7AISiemens Simatic Process HistorianAI+2 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process Historian 2020 (All versions < V2020 SP2… | |
| Analizada | Media (6.5) | 0.62% | — | IBM Infosphere Information Server | 15/8/2024 | 17/6/2026 | IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279. | |
| Analizada | Media (4.9) | 0.63% | — | IBM Infosphere Information Server | 15/8/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277. | |
| Analizada | Media (4.3) | 0.42% | — | IBM Infosphere Information Server | 6/8/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 297429 | |
| Modificada | Crítica (9.8) | 0.54% | — | IBM Infosphere Information ServerIBM Infosphere Information Server ON Cloud | 26/7/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. IBM X-Force ID: 297719. | |
| Modificada | Media (4.6) | 0.24% | — | IBM Infosphere Information Server | 24/7/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. IBM X-Force ID: 294727. | |
| Modificada | Media (5.4) | 0.24% | — | IBM Infosphere Information Server | 12/7/2024 | 17/6/2026 | IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 297720. | |
| Modificada | Media (5.4) | 0.26% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286831. | |
| Modificada | Media (5.4) | 0.26% | — | IBM Infosphere Information Server | 30/6/2024 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 276102. |