Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
936 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 1.9% | — | IBM Websphere Application Server | 23/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4) | 1.1% | — | IBM Websphere Message BrokerIBM Integration BUS | 18/9/2014 | 17/6/2026 | The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtain sensitive information by reading the error page. | |
| Modificada | Media (4) | 1.9% | — | IBM Websphere Portal | 12/9/2014 | 17/6/2026 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, 8.0.0 through 8.0.0.1 CF13, and 8.5.0 before CF02 allows remote authenticated users to cause a denial of service (disk consumption) by uploading large files. | |
| Modificada | Baja (3.5) | 1.4% | — | IBM Websphere Portal | 12/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF13 and 8.5.0 before CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4) | 1.1% | — | IBM Business Process ManagerIBM Websphere Application Server | 4/9/2014 | 17/6/2026 | IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL. | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Business Process ManagerIBM Websphere Application Server | 4/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file. | |
| Modificada | Media (6.5) | 2.7% | — | IBM Websphere Application Server | 22/8/2014 | 17/6/2026 | IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.1) | 2.4% | — | IBM Websphere Application Server | 22/8/2014 | 17/6/2026 | IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial of service (Load Balancer crash) via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | IBM Websphere Application Server | 22/8/2014 | 17/6/2026 | IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | IBM Websphere Application Server | 22/8/2014 | 17/6/2026 | The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | IBM Websphere Application Server | 22/8/2014 | 17/6/2026 | IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition. | |
| Modificada | Media (4.3) | 2.0% | — | IBM Websphere Application Server | 22/8/2014 | 17/6/2026 | IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response. | |
| Modificada | Media (4) | 1.3% | — | IBM Business Process ManagerIBM Websphere Application Server | 17/8/2014 | 17/6/2026 | callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Websphere Datapower SOA Appliance FirmwareIBM Websphere Datapower SOA Appliance | 16/8/2014 | 17/6/2026 | IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sending a large number of requests in an SSL/TLS side-channel… | |
| Modificada | Media (5.8) | 1.8% | — | IBM Websphere Portal | 12/8/2014 | 17/6/2026 | Open redirect vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, 8.0.0 before 8.0.0.1 CF13, and 8.5.0 before CF01 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. | |
| Modificada | Media (5) | 2.1% | — | IBM Websphere Portal | 12/8/2014 | 17/6/2026 | IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes for firewall-traversal requests depending on whether the intranet host exists, which allows remote attackers to map the intranet network via a series of requests. | |
| Modificada | Baja (3.5) | 1.4% | — | IBM Websphere Portal | 12/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF13 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Websphere Portal | 12/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, and 8.0.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Alta (7.5) | 5.1% | — | IBM Lotus NotesIBM Lotus DominoIBM Websphere Real Time | 12/8/2014 | 17/6/2026 | Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allows remote attackers to gain privileges by leveraging the ability to execute code in the context of a security manager. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Websphere PortalIBM Websphere Portal Unified Task List Portlet | 29/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 2.1% | — | IBM Websphere PortalIBM Websphere Portal Unified Task List Portlet | 29/7/2014 | 17/6/2026 | The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive information about environment variables and JAR versions via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.9% | — | IBM Websphere PortalIBM Websphere Portal Unified Task List Portlet | 29/7/2014 | 17/6/2026 | SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5.8) | 1.8% | — | IBM Websphere PortalIBM Websphere Portal Unified Task List Portlet | 29/7/2014 | 17/6/2026 | Multiple open redirect vulnerabilities in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (6.9) | 0.32% | — | IBM Embedded Websphere Application ServerIBM Tivoli Integrated Portal | 29/7/2014 | 17/6/2026 | install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Business Process ManagerIBM Websphere Application Server | 18/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure. |