Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.54% | — | IBM Infosphere Information Server | 19/7/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352. | |
| Modificada | Media (5.3) | 0.71% | — | IBM Infosphere Information Server | 17/7/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in further attacks against the system. IBM X-Force ID: 257695. | |
| Modificada | Crítica (9.8) | 1.4% | — | IBM Infosphere Information Server | 22/5/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285. | |
| Modificada | Media (5.4) | 0.37% | — | IBM Infosphere Information Server | 19/5/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 251213. | |
| Modificada | Media (5.5) | 0.12% | — | IBM Infosphere Information Server | 19/5/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373. | |
| Modificada | Crítica (9.8) | 0.68% | — | IBM Infosphere Information Server | 19/5/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163. | |
| Modificada | Alta (7.5) | 0.60% | — | IBM Infosphere Information ServerIBM JavaIBM Websphere Application ServerIBM Z/transaction Processing Facility | 29/4/2023 | 17/6/2026 | IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188. | |
| Modificada | Media (5.4) | 0.38% | — | IBM Infosphere Information Server | 21/2/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 247646. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Infosphere Information Server | 17/2/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 246333 | |
| Modificada | Media (5.5) | 0.13% | — | IBM Infosphere Information Server | 17/2/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463. | |
| Modificada | Media (4.6) | 0.35% | — | IBM Infosphere Information Server | 8/2/2023 | 17/6/2026 | IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245423. | |
| Modificada | Media (5.4) | 0.43% | — | IBM Infosphere Information Server | 1/2/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 243161. | |
| Modificada | Media (5.3) | 0.71% | — | IBM Infosphere Information Server | 20/1/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable until the process is restarted. IBM X-Force ID: 237583. | |
| Modificada | Crítica (9.8) | 1.8% | — | IBM Infosphere Information ServerIBM Infosphere Information Server ON Cloud | 16/11/2022 | 17/6/2026 | IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687. | |
| Modificada | Media (5.4) | 0.39% | — | IBM Infosphere Information Server | 15/11/2022 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236688. | |
| Modificada | Crítica (9.1) | 1.0% | — | IBM Infosphere Information Server | 3/11/2022 | 17/6/2026 | "IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584." | |
| Modificada | Media (6.5) | 0.65% | — | IBM Infosphere Information Server | 3/11/2022 | 17/6/2026 | "IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input validation. IBM X-Force ID: 235725." | |
| Modificada | Alta (7.8) | 0.58% | — | IBM Infosphere Information Server | 3/11/2022 | 17/6/2026 | "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361. | |
| Modificada | Media (5.4) | 0.44% | — | IBM Infosphere Information Server | 3/11/2022 | 17/6/2026 | "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592." | |
| Modificada | Media (5.4) | 0.43% | — | IBM Infosphere Information Server | 3/11/2022 | 17/6/2026 | "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592. | |
| Modificada | Alta (8.8) | 0.29% | — | IBM Infosphere Information Server | 3/11/2022 | 17/6/2026 | "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a "user that the website trusts. IBM X-Force ID: 227295. | |
| Modificada | Media (6.5) | 0.51% | — | IBM Infosphere Information ServerIBM Infosphere Information Server ON Cloud | 3/11/2022 | 17/6/2026 | "IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427." | |
| Modificada | Crítica (9.8) | 1.2% | — | IBM Infosphere Information Server | 3/11/2022 | 17/6/2026 | "IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598." | |
| Modificada | Media (6.5) | 0.43% | — | IBM Infosphere Information Server | 7/10/2022 | 17/6/2026 | IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699. | |
| Modificada | Media (6.5) | 0.68% | — | IBM Infosphere Information Server | 7/10/2022 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user. |