Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.92%—IBM Websphere MQ10/4/201817/6/2026
IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-middle attack, related to duplication of message data in cleartext outside the protected payload. IBM X-Force ID: 103482.
ModificadaMedia (6.5)2.0%—IBM Websphere MQ30/3/201817/6/2026
A specially crafted message could cause a denial of service in IBM WebSphere MQ 9.0, 9.0.0.1, 9.0.0.2, 9.0.1, 9.0.2, 9.0.3, and 9.0.4 applications consuming messages that it needs to perform data conversion on. IBM X-Force ID: 135520.
ModificadaAlta (7.5)2.2%—IBM Websphere MQ7/2/201817/6/2026
GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.
ModificadaAlta (7.8)0.38%—IBM Websphere MQ9/1/201817/6/2026
IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' user. IBM X-Force ID: 132953.
ModificadaBaja (3.3)0.25%—IBM Websphere MQ4/1/201817/6/2026
IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.
ModificadaMedia (4.3)1.3%—IBM Websphere MQ2/1/201817/6/2026
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that could cause a channel process to cease processing further requests. IBM X-Force ID: 131547.
ModificadaAlta (7.1)0.29%—IBM Websphere MQ11/12/201717/6/2026
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a local user to crash the queue manager agent thread and expose some sensitive information. IBM X-Force ID: 126454.
ModificadaMedia (6.5)1.4%—IBM Websphere MQ7/12/201717/6/2026
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow an authenticated user to insert messages with a corrupt RFH header into the channel which would cause it to restart. IBM X-Force ID: 127803.
ModificadaBaja (3.7)0.98%—IBM Websphere MQ7/12/201717/6/2026
IBM WebSphere MQ 8.0 and 9.0 could allow, under special circumstances, an unauthorized user to access an object which they should have been denied access. IBM X-Force ID: 126456.
ModificadaMedia (4.3)0.94%—IBM Websphere MQ27/11/201717/6/2026
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a shared memory leak by MQ applications using dynamic queues, which can lead to lack of resources for other MQ applications. IBM X-Force ID: 125144.
ModificadaMedia (6.5)2.3%💥 PoCIBM Websphere MQ25/9/201717/6/2026
IBM WebSphere MQ 8.0 could allow an authenticated user to cause a premature termination of a client application thread which could potentially cause denial of service. IBM X-Force ID: 123914.
ModificadaAlta (7.5)1.9%—IBM Websphere MQ Internet Pass-thru2/8/201717/6/2026
IBM WebSphere MQ Internet Pass-Thru 2.0 and 2.1 could allow n attacker to cause the MQIPT to stop responding due to an incorrectly configured security policy. IBM X-Force ID: 121156.
ModificadaMedia (6.5)1.7%—IBM Websphere MQ12/7/201717/6/2026
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to remain in a running state but not process messages. IBM X-Force ID: 125146.
ModificadaAlta (8.1)1.5%—IBM Websphere MQ10/7/201717/6/2026
IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.
ModificadaMedia (4.7)0.29%—IBM Websphere MQ10/7/201717/6/2026
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to obtain sensitive information from WebSphere Application Server traces including user credentials. IBM X-Force ID: 125145.
ModificadaMedia (6.5)1.4%—IBM Websphere MQ6/7/201717/6/2026
IBM WebSphere MQ 9.0.2 could allow an authenticated user to potentially cause a denial of service by saving an incorrect channel status inquiry. IBM X-Force ID: 124354
ModificadaMedia (5.3)1.1%—IBM Websphere MQ21/6/201717/6/2026
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a denial of service to the MQXR channel when trace is enabled. IBM X-Force ID: 121155.
ModificadaMedia (5.5)0.32%—IBM Websphere MQ7/6/201717/6/2026
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.
ModificadaAlta (8.6)1.9%—IBM Websphere MQ20/3/201717/6/2026
IBM WebSphere MQ 8.0.0.6 does not properly terminate channel agents when they are no longer needed, which could allow a user to cause a denial of service through resource exhaustion. IBM Reference #: 1999672.
ModificadaMedia (6.5)0.90%—IBM Websphere MQ7/3/201717/6/2026
IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault which would result in the box having to be rebooted to resume normal operations. IBM Reference #: 1998663.
ModificadaBaja (3.1)0.81%—IBM Websphere MQ24/2/201717/6/2026
IBM WebSphere MQ 8.0 could allow an authenticated user with authority to create a cluster object to cause a denial of service to MQ clustering. IBM Reference #: 1998647.
ModificadaMedia (6.5)1.0%—IBM Websphere MQ22/2/201717/6/2026
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests. IBM Reference #: 1998648.
ModificadaMedia (6.5)0.84%—IBM Websphere MQ22/2/201717/6/2026
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. IBM Reference #: 1998649.
ModificadaMedia (5.9)0.83%—IBM Websphere MQ22/2/201717/6/2026
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man in the middle techniques.
ModificadaMedia (6.5)0.91%—IBM Websphere MQ22/2/201717/6/2026
IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling. IBM Reference #: 1998661.
Orbitaley — Vulnerabilidades