Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
522 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.6% | — | IBM Websphere Application Server | 3/10/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177. | |
| Modificada | Media (5.3) | 1.5% | — | IBM Websphere Application Server | 30/9/2019 | 17/6/2026 | IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the improper setting of a cookie. IBM X-Force ID: 160951. | |
| Modificada | Media (6.3) | 1.0% | — | IBM Websphere Application Server | 30/9/2019 | 17/6/2026 | IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950. | |
| Modificada | Media (5.3) | 2.4% | — | IBM Websphere Application ServerIBM Websphere Virtual Enterprise | 20/9/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL. This can lead the attacker to view any file in a certain directory. IBM X-Force ID: 164364. | |
| Modificada | Media (6.5) | 1.3% | — | IBM Websphere Application Server | 17/9/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive information, caused by improper handling of command line options. IBM X-Force ID: 163997. | |
| Modificada | Media (4.3) | 2.1% | — | IBM Websphere Application Server | 17/9/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the file system. An attacker could send a specially-crafted URL request to view arbitrary files on the system but not content. IBM X-Force ID: 163226. | |
| Modificada | Baja (3.5) | 0.82% | — | IBM Websphere Application Server | 17/9/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter pollution vulnerability. IBM X-Force ID: 160243. | |
| Modificada | Media (5.4) | 0.71% | — | IBM Websphere Application Server | 17/9/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | |
| Modificada | Media (5.3) | 2.7% | — | IBM Websphere Application Server | 17/9/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 160201. | |
| Modificada | Media (5.4) | 1.1% | — | IBM Websphere Application Server | 30/7/2019 | 17/6/2026 | IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP request to hijack the victim's click actions or launch other client-side browser… | |
| Modificada | Alta (7.5) | 2.7% | — | IBM Websphere Application Server | 28/6/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console could allow a remote attacker to obtain sensitive information when a specially crafted url causes a stack trace to be dumped. IBM X-Force ID: 160202. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | IBM Websphere Application Server | 17/5/2019 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445. | |
| Modificada | Media (6.5) | 3.1% | — | IBM Websphere Application Server | 2/4/2019 | 17/6/2026 | IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing. A remote attacker could exploit this to consume all available CPU resources. IBM X-Force ID: 157380. | |
| Modificada | Alta (7.5) | 3.2% | — | IBM Websphere Application Server | 25/3/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers. A remote attacker could exploit this vulnerability to cause the consumption of Memory. IBM X-Force ID: 156242. | |
| Modificada | Media (4.3) | 1.5% | — | IBM Websphere Application Server | 11/3/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information which could be used to launch further attacks against the system. IBM X-Force ID: 152531. | |
| Modificada | Media (5.4) | 0.69% | — | IBM Websphere Application ServerIBM Websphere Virtual Enterprise | 6/3/2019 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155946. | |
| Modificada | Media (5.3) | 1.1% | — | IBM Websphere Application Server | 19/2/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration. A remote attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 154650. | |
| Modificada | Alta (8.8) | 1.2% | — | IBM Websphere Application Server | 12/12/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious URL, a remote attacker could send a specially-crafted request. An attacker could exploit this vulnerability… | |
| Modificada | Alta (8.8) | 1.5% | — | IBM Websphere Application Server | 12/12/2018 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530. | |
| Modificada | Crítica (9.8) | 3.7% | — | IBM Websphere Application Server | 11/12/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533. | |
| Modificada | Media (5.5) | 0.40% | — | IBM Websphere Application Server | 10/12/2018 | 17/6/2026 | IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629. | |
| Modificada | Alta (8.1) | 2.1% | — | IBM Websphere Application Server | 3/12/2018 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID:… | |
| Modificada | Alta (7.1) | 2.5% | — | IBM Websphere Application Server | 26/11/2018 | 17/6/2026 | IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152534. | |
| Modificada | Media (5.5) | 2.0% | — | IBM Websphere Application Server | 16/11/2018 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an attacker could exploit this vulnerability… | |
| Modificada | Media (6.1) | 1.5% | — | IBM Websphere Application Server | 15/11/2018 | 17/6/2026 | The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… |