Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

335 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.3%—Oracle JDKOracle JREDebian LinuxRedhat Satellite+228/8/201717/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require…
ModificadaMedia (5.3)3.5%—Oracle JDKOracle JREOracle JrockitDebian Linux+248/8/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple…
ModificadaAlta (7.5)5.4%—Dell Storage Manager 20164/8/201717/6/2026
Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459.
ModificadaMedia (5.5)0.35%—IBM Tivoli Storage Manager7/6/201717/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.
ModificadaCrítica (9.8)7.5%—ZlibOpensuse LeapOpensuseDebian Linux+3523/5/201714/7/2026
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
ModificadaMedia (5.5)0.31%—IBM Tivoli Storage Manager5/5/201717/6/2026
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472.
ModificadaAlta (8.8)0.94%—IBM Tivoli Storage Manager7/3/201717/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific…
ModificadaAlta (7.2)1.7%—IBM Tivoli Storage Manager24/2/201717/6/2026
IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on the server. IBM Reference #: 1998747.
ModificadaAlta (8.8)0.55%—IBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR VmwareIBM Tivoli Storage Flashcopy Manager FOR Vmware15/2/201717/6/2026
IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1995545.
ModificadaAlta (7.3)1.0%—IBM Tivoli Storage Manager Fastback8/2/201717/6/2026
IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted DLL in the victim's path, an attacker could exploit this vulnerability when the installer is executed to run arbitrary code on the system with privileges of the victim.
ModificadaMedia (4.7)0.30%—IBM Tivoli Storage Manager FOR Space Management8/2/201717/6/2026
IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace output if the password access option is prompt and the password is changed.
ModificadaMedia (6.5)0.33%—IBM Tivoli Storage ManagerIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware1/2/201717/6/2026
IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user.
ModificadaMedia (5.5)0.34%—IBM Tivoli Storage Manager1/2/201717/6/2026
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.
ModificadaMedia (5.4)0.54%—IBM Tivoli Storage Manager1/2/201717/6/2026
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaAlta (8.8)0.55%—IBM Tivoli Storage Manager1/2/201717/6/2026
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
ModificadaMedia (4.3)0.59%—IBM Tivoli Storage Manager1/2/201717/6/2026
IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.
ModificadaAlta (7)0.23%—IBM Tivoli Storage Manager1/2/201717/6/2026
Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.
ModificadaMedia (6.8)1.00%—IBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware1/2/201717/6/2026
IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges.
ModificadaAlta (7.8)0.42%—IBM Tivoli Storage Manager1/2/201717/6/2026
The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer and execute arbitrary code on the system or cause a system crash.
ModificadaAlta (8.5)0.96%—IBM Tivoli Storage Manager FOR Virtual Environments25/11/201617/6/2026
IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 and 7.1.x before 7.1.6 allows remote authenticated users to bypass a TSM credential requirement and obtain administrative access by leveraging multiple simultaneous logins.
ModificadaMedia (5.5)0.32%—IBM Tivoli Storage Manager FOR Space Management12/9/201617/6/2026
IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted password by reading application-trace output.
ModificadaMedia (6.2)0.37%—IBM Tivoli Storage Flashcopy Manager FOR SQL ServerIBM Tivoli Storage Manager FOR Databases Data Protection FOR Microsoft SQL Server8/8/201617/6/2026
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local…
ModificadaBaja (2.5)0.30%—IBM Tivoli Storage Manager3/7/201617/6/2026
IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 before 7.1.6 allows local users to obtain sensitive retrieved data from arbitrary accounts in opportunistic circumstances by leveraging previous use of a symlink during archive and retrieve actions.
AnalizadaCrítica (9.8)92%⚠ Explotación activaOracle JDKOracle JREOracle JrockitOracle Linux+3421/4/201617/6/2026
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
ModificadaAlta (7.5)1.5%—IBM Tivoli Storage Manager Fastback5/4/201617/6/2026
The server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to cause a denial of service (service crash) via crafted packets to a TCP port.
Orbitaley — Vulnerabilidades