Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.16% | — | IBM Sterling Connect\ | 20/1/2026 | 17/6/2026 | IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Sterling Connect\ | 20/1/2026 | 17/6/2026 | IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure… | |
| Analizada | Media (6.1) | 0.21% | — | IBM Sterling Connect\ | 20/1/2026 | 17/6/2026 | IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Analizada | Media (6.5) | 0.18% | — | IBM Sterling Connect\ | 20/1/2026 | 17/6/2026 | IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (6.5) | 0.17% | — | IBM Sterling Connect\ | 20/1/2026 | 17/6/2026 | IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system. | |
| Aplazada | Alta (8.4) | 0.11% | — | IBM Sterling Connect Direct FOR UnixAI | 20/1/2026 | 17/6/2026 | IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to… | |
| Analizada | Alta (7.2) | 0.35% | — | IBM Sterling Connect\ | 30/10/2025 | 17/6/2026 | IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges further due to… | |
| Analizada | Media (5.9) | 0.51% | — | IBM Sterling Connect\ | 22/9/2025 | 17/6/2026 | IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. | |
| Analizada | Media (6.5) | 0.33% | — | IBM Sterling Connect Direct WEB Services | 18/4/2025 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions. | |
| Analizada | Media (6.5) | 0.31% | — | IBM Sterling Connect Direct WEB Services | 18/4/2025 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (4.3) | 0.38% | — | IBM Sterling Connect Direct WEB Services | 19/1/2025 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP address information to authenticated users in responses that could be used in further attacks against the system. | |
| Analizada | Crítica (9.8) | 0.76% | — | IBM Sterling Connect Direct WEB Services | 31/8/2024 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality. | |
| Modificada | Media (5.9) | 0.27% | — | IBM Sterling Connect Direct WEB Services | 22/8/2024 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Analizada | Alta (7.5) | 0.30% | — | IBM Sterling Connect Direct WEB Services | 22/8/2024 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Media (4.3) | 0.18% | — | IBM Sterling Connect Direct WEB Services | 22/8/2024 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Alta (7.5) | 0.70% | — | IBM Sterling Connect\ | 4/3/2024 | 17/6/2026 | IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979. | |
| Modificada | Media (5.4) | 0.35% | — | IBM Sterling Connect\ | 19/7/2023 | 17/6/2026 | IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 252135. | |
| Modificada | Media (5.3) | 0.48% | — | IBM Sterling Connect\ | 19/7/2023 | 17/6/2026 | IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute. IBM X-Force ID: 252055. | |
| Modificada | Alta (7.5) | 0.39% | — | IBM Sterling Connect\ | 19/7/2023 | 17/6/2026 | IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210574. | |
| Modificada | Alta (7.5) | 0.69% | — | IBM Sterling Connect\ | 23/11/2021 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Sterling Connect\ | 23/11/2021 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507. | |
| Modificada | Media (5.4) | 0.64% | — | IBM Sterling Connect Direct User Interface | 26/7/2021 | 17/6/2026 | IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further… | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Sterling Connect\ | 28/10/2020 | 17/6/2026 | IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial of service, caused by a buffer over-read. Bysending a specially crafted request, the attacker could cause the application to crash. IBM X-Force ID: 188906. | |
| Modificada | Alta (7.8) | 0.34% | — | IBM Connect\IBM Sterling Connect\ | 24/8/2020 | 17/6/2026 | IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caused by improper bounds checking. A local attacker could manipulate CD UNIX to obtain root provileges. IBM X-Force ID: 184578. | |
| Modificada | Media (6.7) | 0.39% | — | IBM Sterling Connect\ | 10/4/2019 | 17/6/2026 | IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, and 6.0.0 could allow a user with restricted sudo access on a system to manipulate CD UNIX to gain full sudo access. IBM X-Force ID: 152532. |