Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

176 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)13%—Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Business Process Management Suite+212/1/201917/6/2026
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
ModificadaMedia (6.1)1.3%—IBM Business Automation WorkflowIBM Business Process ManagerIBM Websphere14/12/201817/6/2026
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150947.
ModificadaAlta (7.5)2.9%—Oracle Banking PlatformOracle Business Process Management SuiteOracle Communications Converged Application ServerOracle Communications Webrtc Session Controller+517/10/201817/6/2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.…
ModificadaAlta (8.8)1.7%—IBM Business Automation WorkflowIBM Business Process Manager20/9/201817/6/2026
IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145109.
ModificadaAlta (7.5)9.4%💥 PoCApache TikaOracle Business Process Management Suite19/9/201817/6/2026
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
ModificadaCrítica (9.1)2.7%—Oracle Business Process Management Suite18/7/201817/6/2026
Vulnerability in the Oracle Business Process Management Suite component of Oracle Fusion Middleware (subcomponent: Process Analysis & Discovery). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with…
ModificadaCrítica (9.8)4.8%—Bouncycastle Bc-javaNetapp Oncommand Workflow AutomationOpensuse LeapOracle API Gateway+209/7/201817/6/2026
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an…
ModificadaAlta (7.5)3.6%—Bouncycastle Bc-javaBouncycastle Fips Java APIDebian LinuxOracle API Gateway+165/6/201817/6/2026
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA…
ModificadaMedia (5.4)1.0%—IBM Business Process ManagerIBM Websphere Enterprise Service BUSIBM Websphere Process ServerIBM Business Process Manager Enterprise Service BUS30/3/201817/6/2026
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135.
ModificadaMedia (5.4)1.0%—IBM Business Process Manager30/3/201817/6/2026
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136152.
ModificadaMedia (4.3)0.73%—IBM Business Process Manager30/3/201817/6/2026
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.
ModificadaMedia (4.3)1.4%—IBM Business Process ManagerIBM Business Process Manager Enterprise Service BUS30/3/201817/6/2026
IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive information about the application server. IBM X-Force ID: 136150.
ModificadaBaja (3.3)0.38%—IBM Business Process ManagerIBM Business Process Manager Enterprise Service BUSIBM Websphere30/3/201817/6/2026
IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.
ModificadaMedia (4.3)0.72%—IBM Business Process Manager15/3/201817/6/2026
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.
ModificadaAlta (8.8)1.6%—Redwood SAP Business Process Automation14/3/201817/6/2026
SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnerability.
ModificadaAlta (7.5)1.6%—Redwood SAP Business Process Automation14/3/201817/6/2026
Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access information which would otherwise be restricted.
ModificadaMedia (4.3)1.5%—Redwood SAP Business Process Automation14/3/201817/6/2026
SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.
ModificadaAlta (7.5)6.4%—HP Business Process Monitor15/2/201817/6/2026
A Remote Unauthorized Access to Data vulnerability in HPE Business Process Monitor version v09.2x, v09.30 was found.
ModificadaMedia (6.1)1.4%—Nagios Business Process Intelligence6/2/201817/6/2026
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.
ModificadaAlta (8.8)0.97%—IBM Business Process Manager24/1/201817/6/2026
IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 136783.
ModificadaMedia (6.1)30%💥 PoCJqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+4318/1/201817/6/2026
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
ModificadaMedia (5.4)0.80%—IBM Business Process Manager20/12/201717/6/2026
IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692.
ModificadaMedia (6.5)1.8%—IBM Business Process Manager27/11/201717/6/2026
IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorization checks.
ModificadaMedia (6.1)0.64%—Wso2 Application ServerWso2 Business Process ServerWso2 Business Rules ServerWso2 Complex Event Processor+44/10/201717/6/2026
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.
ModificadaAlta (8.8)1.5%—IBM Business Process Manager26/9/201717/6/2026
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.
Orbitaley — Vulnerabilidades