Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
302 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.40% | — | IBM Security Access ManagerIBM Tivoli Federated Identity Manager | 8/3/2018 | 17/6/2026 | An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without… | |
| Modificada | Media (6.1) | 0.78% | — | Netiq Identity Manager | 5/3/2018 | 17/6/2026 | Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in the context of vulnerable application, via user.Context in the Object Selector, via vdtData in the… | |
| Modificada | Alta (7.5) | 1.1% | — | Netiq Identity Manager | 2/3/2018 | 17/6/2026 | Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar. | |
| Modificada | Alta (7.2) | 0.87% | — | Netiq Identity Manager | 2/3/2018 | 17/6/2026 | NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users. | |
| Modificada | Crítica (9.8) | 0.91% | — | Netiq Identity Manager | 2/3/2018 | 17/6/2026 | The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables. | |
| Modificada | Crítica (9.8) | 0.84% | — | Netiq Identity Manager | 2/3/2018 | 17/6/2026 | In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles. | |
| Modificada | Crítica (9.1) | 1.1% | — | Netiq Identity Manager | 1/3/2018 | 17/6/2026 | The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial of service attacks. | |
| Modificada | Media (6.1) | 2.4% | — | Microsoft Identity Manager | 26/2/2018 | 17/6/2026 | Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2016 server, aka "Microsoft Identity Manager XSS Elevation of Privilege Vulnerability." | |
| Modificada | Media (4.3) | 0.95% | — | IBM Security Identity Manager Virtual Appliance | 21/2/2018 | 17/6/2026 | IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072. | |
| Modificada | Baja (3.7) | 0.64% | — | IBM Security Privileged Identity Manager | 21/2/2018 | 17/6/2026 | IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071. | |
| Modificada | Baja (3.7) | 1.0% | — | IBM Security Identity Manager Virtual Appliance | 21/2/2018 | 17/6/2026 | IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890. | |
| Modificada | Crítica (9.8) | 8.4% | — | Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Satellite+20 | 6/2/2018 | 17/6/2026 | A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting… | |
| Modificada | Media (5.4) | 0.64% | — | IBM Security Identity Manager | 12/1/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111737. | |
| Modificada | Alta (8.8) | 0.78% | — | IBM Security Identity Manager | 12/1/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. IBM X-Force ID: 111736. | |
| Modificada | Crítica (9.8) | 2.3% | — | IBM Security Identity Manager Virtual Appliance | 12/1/2018 | 17/6/2026 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. IBM X-Force ID: 111695. | |
| Modificada | Alta (7.8) | 0.31% | — | IBM Security Identity Manager Virtual Appliance | 12/1/2018 | 17/6/2026 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors. IBM X-Force ID: 111643. | |
| Modificada | Alta (8.8) | 3.7% | — | IBM Security Identity Manager Virtual Appliance | 12/1/2018 | 17/6/2026 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges via unspecified vectors. IBM X-Force ID: 111640. | |
| Modificada | Crítica (10) | 3.9% | — | Oracle Identity Manager | 30/10/2017 | 17/6/2026 | Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity… | |
| Modificada | Alta (8.2) | 0.49% | — | Oracle Identity Manager Connector | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware (subcomponent: Microsoft Active Directory). The supported version that is affected is 9.1.1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Identity Manager… | |
| Modificada | Alta (8.6) | 1.5% | — | IBM Security Identity Governance AND IntelligenceIBM Security Identity ManagerIBM Security Privileged Identity Manager | 28/9/2017 | 17/6/2026 | IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621. | |
| Modificada | Alta (8.8) | 3.4% | — | IBM Security Identity Governance AND IntelligenceIBM Security Identity ManagerIBM Security Privileged Identity Manager | 28/9/2017 | 17/6/2026 | IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394. | |
| Modificada | Alta (7.8) | 0.30% | — | IBM Security Identity Manager | 25/9/2017 | 17/6/2026 | IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801. | |
| Modificada | Crítica (9.8) | 1.7% | — | CA Identity ManagerCA Identity Manager Virtual Appliance | 22/9/2017 | 17/6/2026 | CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search. | |
| Modificada | Alta (8.8) | 0.92% | — | IBM Security Identity Manager | 18/9/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Tivoli Federated Identity Manager | 8/6/2017 | 17/6/2026 | IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731. |