Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

302 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)0.40%—IBM Security Access ManagerIBM Tivoli Federated Identity Manager8/3/201817/6/2026
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without…
ModificadaMedia (6.1)0.78%—Netiq Identity Manager5/3/201817/6/2026
Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in the context of vulnerable application, via user.Context in the Object Selector, via vdtData in the…
ModificadaAlta (7.5)1.1%—Netiq Identity Manager2/3/201817/6/2026
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.
ModificadaAlta (7.2)0.87%—Netiq Identity Manager2/3/201817/6/2026
NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.
ModificadaCrítica (9.8)0.91%—Netiq Identity Manager2/3/201817/6/2026
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
ModificadaCrítica (9.8)0.84%—Netiq Identity Manager2/3/201817/6/2026
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
ModificadaCrítica (9.1)1.1%—Netiq Identity Manager1/3/201817/6/2026
The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial of service attacks.
ModificadaMedia (6.1)2.4%—Microsoft Identity Manager26/2/201817/6/2026
Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2016 server, aka "Microsoft Identity Manager XSS Elevation of Privilege Vulnerability."
ModificadaMedia (4.3)0.95%—IBM Security Identity Manager Virtual Appliance21/2/201817/6/2026
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072.
ModificadaBaja (3.7)0.64%—IBM Security Privileged Identity Manager21/2/201817/6/2026
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071.
ModificadaBaja (3.7)1.0%—IBM Security Identity Manager Virtual Appliance21/2/201817/6/2026
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.
ModificadaCrítica (9.8)8.4%—Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Satellite+206/2/201817/6/2026
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting…
ModificadaMedia (5.4)0.64%—IBM Security Identity Manager12/1/201817/6/2026
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111737.
ModificadaAlta (8.8)0.78%—IBM Security Identity Manager12/1/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. IBM X-Force ID: 111736.
ModificadaCrítica (9.8)2.3%—IBM Security Identity Manager Virtual Appliance12/1/201817/6/2026
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. IBM X-Force ID: 111695.
ModificadaAlta (7.8)0.31%—IBM Security Identity Manager Virtual Appliance12/1/201817/6/2026
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors. IBM X-Force ID: 111643.
ModificadaAlta (8.8)3.7%—IBM Security Identity Manager Virtual Appliance12/1/201817/6/2026
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges via unspecified vectors. IBM X-Force ID: 111640.
ModificadaCrítica (10)3.9%—Oracle Identity Manager30/10/201717/6/2026
Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity…
ModificadaAlta (8.2)0.49%—Oracle Identity Manager Connector19/10/201717/6/2026
Vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware (subcomponent: Microsoft Active Directory). The supported version that is affected is 9.1.1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Identity Manager…
ModificadaAlta (8.6)1.5%—IBM Security Identity Governance AND IntelligenceIBM Security Identity ManagerIBM Security Privileged Identity Manager28/9/201717/6/2026
IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621.
ModificadaAlta (8.8)3.4%—IBM Security Identity Governance AND IntelligenceIBM Security Identity ManagerIBM Security Privileged Identity Manager28/9/201717/6/2026
IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394.
ModificadaAlta (7.8)0.30%—IBM Security Identity Manager25/9/201717/6/2026
IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801.
ModificadaCrítica (9.8)1.7%—CA Identity ManagerCA Identity Manager Virtual Appliance22/9/201717/6/2026
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.
ModificadaAlta (8.8)0.92%—IBM Security Identity Manager18/9/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors.
ModificadaAlta (7.5)1.0%—IBM Tivoli Federated Identity Manager8/6/201717/6/2026
IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731.
Orbitaley — Vulnerabilidades