Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.33%—IBM Infosphere Optim Data Growth FOR Oracle E-business Suite10/10/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to hijack the authentication of arbitrary users.
ModificadaMedia (4.3)0.59%—IBM Infosphere Optim Data Growth FOR Oracle E-business Suite10/10/201316/6/2026
The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote attackers to impersonate arbitrary users by leveraging access to a legitimate user's web browser either (1) before or (2) after authentication.
ModificadaMedia (5.2)0.56%—IBM Infosphere Optim Data Growth FOR Oracle E-business Suite10/10/201316/6/2026
The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to bypass intended access restrictions and create, modify, or delete documents or scripts via unspecified vectors.
ModificadaMedia (5)1.2%—IBM Infosphere Optim Data Growth FOR Oracle E-business Suite27/5/201316/6/2026
The Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not provide an encrypted session for transmitting login credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
ModificadaBaja (3.5)0.76%—IBM Infosphere Optim Data Growth FOR Oracle E-business Suite27/5/201316/6/2026
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
ModificadaAlta (7.5)1.1%—IBM Infosphere Optim Data Growth FOR Oracle E-business Suite27/5/201316/6/2026
SQL injection vulnerability in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaBaja (3.5)0.76%—IBM Infosphere Optim Data Growth FOR Oracle E-business Suite27/5/201316/6/2026
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, related to a stored XSS issue.
ModificadaMedia (5)1.3%—IBM Infosphere Optim Data Growth FOR Oracle E-business Suite27/5/201316/6/2026
The login page in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not limit the number of incorrect authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
ModificadaMedia (4.3)0.48%—IBM Infosphere Optim Data Growth FOR Oracle E-business Suite27/5/201316/6/2026
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 relies on the MD5 algorithm for signatures in X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Orbitaley — Vulnerabilidades