Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.7)0.21%—Wso2 Enterprise IntegratorWso2 Enterprise Service BUS16/10/202517/6/2026
An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs and user-store configuration. A low-privileged user can access log data and user-store configuration details that are not intended to…
AnalizadaMedia (6.5)0.56%—Wso2 API Control PlaneWso2 API ManagerWso2 API Manager AnalyticsWso2 Data Analytics Server+1116/10/202525/9/2026
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This…
ModificadaMedia (5.3)1.8%—IBM Business Automation WorkflowIBM Business Process ManagerIBM Business Process Manager Enterprise Service BUSIBM Websphere Enterprise Service BUS8/4/201917/6/2026
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request. IBM X-Force ID: 152020.
ModificadaMedia (5.4)1.0%—IBM Business Process ManagerIBM Websphere Enterprise Service BUSIBM Websphere Process ServerIBM Business Process Manager Enterprise Service BUS30/3/201817/6/2026
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135.
ModificadaMedia (4.3)1.4%—IBM Business Process ManagerIBM Business Process Manager Enterprise Service BUS30/3/201817/6/2026
IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive information about the application server. IBM X-Force ID: 136150.
ModificadaBaja (3.3)0.38%—IBM Business Process ManagerIBM Business Process Manager Enterprise Service BUSIBM Websphere30/3/201817/6/2026
IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.
ModificadaMedia (4.3)1.8%—IBM Business Process ManagerIBM Websphere Enterprise Service BUSIBM Websphere Process Server16/12/201417/6/2026
IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for…
ModificadaBaja (3.5)0.90%—Redhat Jboss Enterprise Service BUSRedhat Jboss Enterprise SOA Platform10/8/201016/6/2026
JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.
Orbitaley — Vulnerabilidades