Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.22%—IBM Spectrum Protect Operations Center13/12/202117/6/2026
IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Force ID: 209610.
ModificadaMedia (5.9)0.59%—IBM Spectrum Protect Plus13/12/202117/6/2026
The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.
ModificadaMedia (5.5)0.20%—IBM Spectrum Protect Plus29/6/202117/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791.
ModificadaAlta (7.5)0.71%—IBM Spectrum Protect Plus26/4/202117/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258.
ModificadaAlta (7.8)0.34%—IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space Management26/4/202117/6/2026
IBM Spectrum Protect Client 8.1.0.0-8 through 1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when processing the current locale settings. A local attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges or cause the application to…
ModificadaMedia (5.5)0.27%—IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space Management26/4/202117/6/2026
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and cause the application to crash. IBM X-Force ID: 198934
ModificadaMedia (6.2)0.27%—IBM Spectrum Protect Plus26/4/202117/6/2026
IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.
ModificadaAlta (7.8)0.21%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments26/4/202117/6/2026
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811.
ModificadaMedia (6.5)0.75%—IBM Spectrum Protect Plus26/4/202117/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 196344.
ModificadaMedia (4.4)0.26%—IBM Spectrum Protect16/4/202117/6/2026
IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking during the parsing of commands. By issuing such a command with an improper parameter, an authorized administrator could overflow a buffer and cause the server to crash. IBM X-Force ID: 197792.
ModificadaMedia (4.8)0.46%—IBM Spectrum Protect Operations Center15/2/202117/6/2026
IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows certain cache values to be set and dumped to a file. By setting a grossly large cache value and dumping that cached value to a file multiple times, a remote attacker could exploit this vulnerability to…
ModificadaAlta (8)0.70%—IBM Spectrum Protect Operations Center15/2/202117/6/2026
IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter validation. By creating an unspecified servlet request with specially crafted input parameters, an attacker could exploit this vulnerability to load a malicious .dll…
ModificadaMedia (5.4)0.59%—IBM Spectrum Protect Operations Center15/2/202117/6/2026
IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session using an attacker controlled IBM Spectrum Protect server, an attacker could exploit this…
ModificadaAlta (7.5)2.3%—IBM Spectrum Protect Plus10/2/202117/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to excess resource consumption. IBM X-Force ID: 193659.
ModificadaMedia (5.3)1.0%—IBM Spectrum Protect Plus8/1/202117/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658.
ModificadaMedia (4.4)0.25%—IBM Spectrum Protect Plus8/1/202117/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657.
ModificadaMedia (6.1)0.90%—IBM Spectrum Protect Plus8/1/202117/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the…
ModificadaMedia (6.5)1.3%—IBM Spectrum Protect Plus8/1/202117/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct…
ModificadaAlta (7.5)0.68%—IBM Spectrum Protect Plus8/1/202117/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654.
ModificadaMedia (5.5)0.29%—IBM Spectrum Protect8/1/202117/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their intended role and permissions. IBM X-Force ID: 193653.
ModificadaCrítica (9.8)2.4%—IBM Spectrum Protect Plus23/11/202017/6/2026
IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 190454.
ModificadaMedia (5.9)1.2%—IBM Spectrum Protect Plus23/11/202017/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 189214.
ModificadaMedia (5.3)1.6%—IBM Spectrum Protect Operations Center23/11/202017/6/2026
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the websocket event stream, an attacker could exploit this…
ModificadaMedia (6.5)2.6%—IBM Spectrum Protect Plus15/9/202017/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 187501.
ModificadaAlta (8)1.8%—IBM Spectrum Protect Plus15/9/202017/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.
Orbitaley — Vulnerabilidades