Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 2.3% | — | IBM Datapower Gateway | 7/12/2018 | 17/6/2026 | IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force… | |
| Modificada | Alta (7.1) | 1.9% | — | IBM Datapower Gateway | 25/9/2018 | 17/6/2026 | IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit… | |
| Modificada | Alta (7.8) | 0.38% | — | IBM Datapower Gateway | 25/9/2018 | 17/6/2026 | IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. IBM X-Force ID:… | |
| Modificada | Alta (7.1) | 1.4% | — | IBM Datapower Gateway | 4/4/2018 | 17/6/2026 | IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139023. | |
| Modificada | Media (4) | 0.33% | — | IBM Datapower Gateway | 31/1/2018 | 17/6/2026 | IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817. | |
| Modificada | Media (6.1) | 0.96% | — | IBM Datapower Gateway | 28/9/2017 | 17/6/2026 | IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132368. | |
| Modificada | Baja (2.7) | 1.7% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 2/7/2016 | 17/6/2026 | Buffer overflow in the CLI on IBM WebSphere DataPower XC10 appliances 2.1 and 2.5 allows remote authenticated users to cause a denial of service via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | IBM Datapower Gateway | 14/11/2015 | 17/6/2026 | IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting… | |
| Modificada | Baja (2.6) | 1.0% | — | IBM Datapower Gateway | 8/11/2015 | 17/6/2026 | The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack. | |
| Modificada | Baja (2.1) | 0.33% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 3/8/2015 | 17/6/2026 | The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and attaching it elsewhere. | |
| Modificada | Media (6.8) | 1.7% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 6/4/2015 | 17/6/2026 | The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obtain sensitive information or modify data, via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 12/12/2014 | 17/6/2026 | The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to bypass intended grid-data access restrictions via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 11/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Baja (2.1) | 0.33% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 11/12/2014 | 17/6/2026 | The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows local users to obtain sensitive information by reading a response. | |
| Modificada | Media (6) | 0.52% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 11/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Modificada | Alta (10) | 2.4% | — | IBM Websphere Datapower Xc10 Appliance FirmwareIBM Websphere Datapower Xc10 Appliance | 2/10/2014 | 17/6/2026 | Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network and capturing a session cookie. | |
| Modificada | Alta (10) | 2.4% | — | IBM Websphere Datapower Xc10 Appliance FirmwareIBM Websphere Datapower Xc10 Appliance | 2/10/2014 | 17/6/2026 | Unspecified vulnerability in the Administrative Console on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Websphere Datapower SOA Appliance FirmwareIBM Websphere Datapower SOA Appliance | 16/8/2014 | 17/6/2026 | IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sending a large number of requests in an SSL/TLS side-channel… | |
| Modificada | Alta (10) | 1.7% | — | IBM Websphere Datapower Xc10 ApplianceIBM Websphere Datapower Xc10 Appliance Firmware | 22/10/2013 | 16/6/2026 | The console on IBM WebSphere DataPower XC10 appliances 2.1.0 and 2.5.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors. | |
| Modificada | Alta (7.1) | 1.7% | — | IBM Websphere Datapower Xc10 ApplianceIBM Websphere Datapower Xc10 Appliance Firmware | 22/10/2013 | 16/6/2026 | IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Alta (10) | 2.4% | — | IBM Websphere Datapower Xc10 Appliance Firmware | 27/9/2013 | 16/6/2026 | Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.0 through 2.5.0.1 allows remote attackers to obtain administrative access via unknown vectors. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Websphere Datapower Xc10 Appliance FirmwareIBM Websphere Datapower Xc10 ApplianceIBM Websphere Datapower Service Gateway Xg45 Virtual Edition FirmwareIBM Websphere Datapower Service Gateway Xg45 Virtual Edition+10 | 28/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web… | |
| Modificada | Alta (9.3) | 2.7% | — | IBM Websphere Datapower Xc10 Appliance FirmwareIBM Websphere Datapower Xc10 Appliance | 9/5/2013 | 16/6/2026 | Unspecified vulnerability on IBM WebSphere DataPower XC10 Appliance devices 2.0 and 2.1 through 2.1 FP3 allows remote attackers to bypass authentication and perform administrative actions via unknown vectors. | |
| Modificada | Alta (9) | 2.2% | — | IBM Websphere Datapower Xc10 Appliance | 23/11/2012 | 16/6/2026 | The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended administrative-role requirements and perform arbitrary JMX operations via unspecified vectors. | |
| Modificada | Alta (7.8) | 2.4% | — | IBM Websphere Datapower Xc10 Appliance | 23/11/2012 | 16/6/2026 | The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified interface, which allows remote attackers to cause a denial of service (process exit) via unknown vectors. |