Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 2.1% | — | IBM Business Process Manager | 17/12/2014 | 17/6/2026 | Directory traversal vulnerability in an export function in the Process Center in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Business Process Manager | 17/12/2014 | 17/6/2026 | The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows remote authenticated users to bypass intended access restrictions via a project action for a (1) process application or (2) toolkit. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Business Process ManagerIBM Websphere Enterprise Service BUSIBM Websphere Process Server | 16/12/2014 | 17/6/2026 | IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for… | |
| Modificada | Media (4.3) | 1.2% | — | IBM Business Process Manager | 31/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the redirect-login feature in IBM Business Process Manager (BPM) Advanced 7.5 through 8.5.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4) | 1.1% | — | IBM Business Process Manager | 7/10/2014 | 17/6/2026 | The Saved Search Admin component in the Process Admin Console in IBM Business Process Manager (BPM) 8.0 through 8.5.5 does not properly restrict task and instance listings in result sets, which allows remote authenticated users to bypass authorization checks and obtain sensitive information by executing a saved search. | |
| Modificada | Media (4) | 1.1% | — | IBM Business Process Manager | 4/9/2014 | 17/6/2026 | An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search results. | |
| Modificada | Media (4) | 1.1% | — | IBM Business Process ManagerIBM Websphere Application Server | 4/9/2014 | 17/6/2026 | IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL. | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Business Process ManagerIBM Websphere Application Server | 4/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file. | |
| Modificada | Media (4) | 1.3% | — | IBM Business Process ManagerIBM Websphere Application Server | 17/8/2014 | 17/6/2026 | callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (5) | 2.1% | — | IBM Business Process Manager | 11/8/2014 | 17/6/2026 | IBM Business Process Manager (BPM) 8.5 through 8.5.5 allows remote attackers to obtain potentially sensitive information by visiting an unspecified JSP diagnostic page. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Business Process ManagerIBM Websphere Application Server | 18/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure. | |
| Modificada | Media (6) | 1.1% | — | IBM Business Process Manager | 10/4/2014 | 17/6/2026 | The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does not verify authorization for read or write access to attribute values, which allows remote authenticated users to obtain sensitive information, configure e-mail… | |
| Modificada | Media (4.3) | 1.2% | — | IBM Filenet Case FoundationIBM Filenet Content ManagerIBM Filenet P8 Business Process Manager | 22/1/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache ArchivaApache StrutsFujitsu Interstage Business Process Manager AnalyticsOracle Siebel Apps - E-billing | 20/7/2013 | 16/6/2026 | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix. | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Business Process Manager | 6/7/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Business Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 before FP1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) ProcessPortal/jsp/socialPortal/dashboard.jsp, (2) teamworks/executeServiceByName, (3)… | |
| Modificada | Media (5) | 1.2% | — | IBM Filenet P8 Content EngineIBM Filenet P8 Business Process ManagerIBM Filenet P8 Content Manager | 21/2/2011 | 16/6/2026 | IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an… |