Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

302 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.33%—IBM Security Privileged Identity Manager7/6/201717/6/2026
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.
ModificadaMedia (5.3)1.3%—IBM Security Privileged Identity Manager7/6/201717/6/2026
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136.
ModificadaMedia (5.4)0.52%—IBM Tivoli Federated Identity Manager22/5/201717/6/2026
IBM Tivoli Federated Identity Manager 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125732.
ModificadaCrítica (9.9)2.4%—Oracle Identity Manager24/4/201717/6/2026
Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Rules Engine). The supported version that is affected is 11.1.2.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the…
ModificadaCrítica (9.8)90%💥 ExploitApache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7517/4/201717/6/2026
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
ModificadaAlta (7.8)0.36%—IBM Security Identity Manager1/2/201717/6/2026
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
ModificadaMedia (6.1)0.96%—IBM Security Identity Manager Virtual Appliance1/2/201717/6/2026
IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaBaja (2.4)0.35%—IBM Security Identity Manager Virtual Appliance1/2/201717/6/2026
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
ModificadaMedia (6.3)0.64%—IBM Security Privileged Identity Manager1/2/201717/6/2026
IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically executed by the server.
ModificadaMedia (6.5)0.99%—IBM Security Privileged Identity Manager1/2/201717/6/2026
IBM Security Privileged Identity Manager Virtual Appliance could disclose sensitive information in generated error messages that would be available to an authenticated user.
ModificadaMedia (5.9)1.2%—IBM Security Privileged Identity Manager1/2/201717/6/2026
IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
ModificadaCrítica (9.8)1.6%—IBM Security Privileged Identity Manager1/2/201717/6/2026
IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
ModificadaAlta (7.5)1.7%—IBM Security Privileged Identity Manager1/2/201717/6/2026
IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain…
ModificadaMedia (5.3)2.1%—Vmware Identity ManagerVmware Vrealize Automation29/12/201617/6/2026
VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
ModificadaMedia (6.5)0.88%—IBM Security Privileged Identity Manager24/11/201617/6/2026
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, allows remote authenticated users to append to arbitrary files via unspecified vectors.
ModificadaBaja (3.7)0.88%—IBM Security Privileged Identity Manager24/11/201617/6/2026
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
ModificadaMedia (5.4)0.56%—Novell Identity ManagerNovell Identity Manager Identity Applications27/10/201617/6/2026
XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.
ModificadaMedia (6.1)0.77%—Netiq Identity Manager27/10/201617/6/2026
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
ModificadaMedia (6.1)0.77%—Netiq Identity Manager27/10/201617/6/2026
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.
ModificadaBaja (3.1)0.37%—Oracle Identity Manager25/10/201617/6/2026
Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware allows local users to affect confidentiality and integrity via vectors related to App Server.
ModificadaMedia (5.4)0.62%—IBM Security Privileged Identity Manager Virtual Appliance26/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.
ModificadaMedia (6.8)0.76%—IBM Security Privileged Identity Manager Virtual Appliance26/9/201617/6/2026
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
ModificadaAlta (7.1)1.1%—IBM Security Privileged Identity Manager Virtual Appliance26/9/201617/6/2026
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML…
ModificadaMedia (6.5)1.6%—IBM Security Privileged Identity Manager Virtual Appliance26/9/201617/6/2026
Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
ModificadaAlta (8.8)1.6%—IBM Security Privileged Identity Manager Virtual Appliance26/9/201617/6/2026
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
Orbitaley — Vulnerabilidades