Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.51%—Lifplatforms LIF Authentication Server4/10/202417/6/2026
Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct code. If the attacker knew the email of…
ModificadaAlta (7.5)0.50%—Mfasoft Secure Authentication Server16/9/202417/6/2026
An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user tokens without authentication. The is a brute-force attack on the serial parameter by…
ModificadaMedia (5.5)0.17%—IBM Sterling External Authentication Server5/9/202317/6/2026
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations. IBM X-Force ID: 252139.
ModificadaMedia (5.5)0.19%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy5/9/202317/6/2026
IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.
ModificadaMedia (5.5)0.12%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy8/2/202317/6/2026
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a local attacker to decrypt sensitive information. IBM X-Force ID: 231373.
ModificadaMedia (5.3)0.87%—IBM Secure External Authentication ServerIBM Sterling Secure Proxy17/5/202217/6/2026
IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the host due to improper validation of certificates. IBM X-Force ID: 201104.
ModificadaMedia (4.3)1.0%—IBM Sterling External Authentication Server24/2/202217/6/2026
IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144.
ModificadaAlta (7.5)2.0%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy23/2/202217/6/2026
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.
ModificadaMedia (6.5)0.58%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy23/2/202217/6/2026
IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted. A local attacker positioned inside the Secure Zone…
ModificadaMedia (4.9)0.99%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy30/8/202117/6/2026
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 201160.
ModificadaAlta (7.5)0.92%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy30/8/202117/6/2026
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100.
ModificadaAlta (7.5)0.92%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy30/8/202117/6/2026
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095.
ModificadaMedia (5.4)0.83%—IBM Secure External Authentication ServerIBM Sterling Secure Proxy15/7/202117/6/2026
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201777.
ModificadaAlta (7.5)2.9%—IBM Secure External Authentication ServerIBM Sterling Secure Proxy15/7/202117/6/2026
IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.
ModificadaAlta (8.2)3.2%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy16/7/202017/6/2026
IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or…
ModificadaAlta (7.8)0.58%—IBM Sterling External Authentication Server11/2/202016/6/2026
A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malicious user execute arbitrary code.
ModificadaCrítica (9.8)1.5%—Xm-online Xm^online 2 User Account AND Authentication Server26/8/201917/6/2026
XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.
ModificadaBaja (3.5)1.2%—Vasco Identikey Authentication Server13/1/201417/6/2026
VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of this one-time password and a multiple-time AD password.
ModificadaMedia (5)4.4%—DS3 Authentication Server28/6/201316/6/2026
ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter.
ModificadaMedia (5)7.3%—DS3 Authentication Server28/6/201316/6/2026
ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in a -REG-E-OPEN error message.
ModificadaAlta (9)9.1%—DS3 Authentication Server28/6/201316/6/2026
ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via shell metacharacters in the HOST_NAME field.
ModificadaMedia (5.8)1.4%—Arcot Webfort Versatile Authentication Server5/5/201116/6/2026
Open redirect vulnerability in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (4.3)1.3%—Arcot Webfort Versatile Authentication Server5/5/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.