Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.5% | — | Eclipse MojarraOracle Mojarra Javaserver FacesOracle Application Testing SuiteOracle Banking Enterprise Product Manufacturing+19 | 2/10/2019 | 17/6/2026 | faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled. | |
| Modificada | Media (6.5) | 3.8% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jOracle Application Performance Management+14 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys. | |
| Modificada | Media (6.5) | 2.5% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jOracle Application Performance Management+12 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys. | |
| Modificada | Media (6.5) | 1.7% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jMcafee Threat Intelligence Exchange Server+12 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key. | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Crítica (9.8) | 89% | — | Oracle Communications Diameter Signaling RouterOracle Communications Network IntegrityOracle Hyperion Infrastructure TechnologyOracle Identity Manager+5 | 19/6/2019 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic… | |
| Modificada | Media (4.4) | 0.25% | — | Intel Open Cloud Integrity TehnologyIntel Openattestation | 13/6/2019 | 17/6/2026 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Baja (3.3) | 0.26% | — | Intel Open Cloud Integrity TehnologyIntel Openattestation | 13/6/2019 | 17/6/2026 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Baja (3.3) | 0.26% | — | Intel Open Cloud Integrity TehnologyIntel Openattestation | 13/6/2019 | 17/6/2026 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.7) | 0.31% | — | Intel Open Cloud Integrity TehnologyIntel Openattestation | 13/6/2019 | 17/6/2026 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.25% | — | Intel Open Cloud Integrity TehnologyIntel Openattestation | 13/6/2019 | 17/6/2026 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.25% | — | Intel Open Cloud Integrity TehnologyIntel Openattestation | 13/6/2019 | 17/6/2026 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Baja (3.6) | 0.23% | — | Intel Open Cloud Integrity TehnologyIntel Openattestation | 13/6/2019 | 17/6/2026 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.34% | — | Intel Open Cloud Integrity TehnologyIntel Openattestation | 13/6/2019 | 17/6/2026 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.25% | — | Intel Open Cloud Integrity TehnologyIntel Openattestation | 13/6/2019 | 17/6/2026 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.5) | 92% | — | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+33 | 1/5/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version… | |
| Modificada | Alta (7.5) | 1.5% | — | GHS Integrity Rtos | 26/3/2019 | 17/6/2026 | An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The main shell handler function uses the value of the environment variable ipcom.shell.greeting as the first argument to printf(). Setting this variable using the sysvar command results in a user-controlled format… | |
| Modificada | Crítica (9.8) | 2.1% | — | GHS Integrity Rtos | 26/3/2019 | 17/6/2026 | An issue was discovered in Interpeak IPWEBS on Green Hills INTEGRITY RTOS 5.0.4. It allocates 60 bytes for the HTTP Authentication header. However, when copying this header to parse, it does not check the size of the header, leading to a stack-based buffer overflow. | |
| Modificada | Crítica (9.8) | 1.9% | — | GHS Integrity Rtos | 26/3/2019 | 17/6/2026 | An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. There is a heap-based buffer overflow in the function responsible for printing the shell prompt, when a custom modifier is used to display information such as a process ID, IP address, or current working directory.… | |
| Modificada | Alta (7.5) | 1.5% | — | GHS Integrity Rtos | 26/3/2019 | 17/6/2026 | An issue was discovered in handler_ipcom_shell_pwd in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. When using the pwd command, the current working directory path is used as the first argument to printf() without a proper check. An attacker may thus forge a path containing format string… | |
| Modificada | Alta (7.5) | 1.5% | — | GHS Integrity Rtos | 26/3/2019 | 17/6/2026 | An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The undocumented shell command "prompt" sets the (user controlled) shell's prompt value, which is used as a format string input to printf, resulting in an information leak of memory addresses. | |
| Modificada | Media (6.1) | 11% | — | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+34 | 2/8/2018 | 17/6/2026 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | |
| Modificada | Alta (7.5) | 3.2% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Network Integrity+24 | 25/6/2018 | 17/6/2026 | Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not… | |
| Modificada | Media (5.9) | 2.7% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Diameter Signaling Router+29 | 25/6/2018 | 25/8/2026 | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a… | |
| Modificada | Alta (8.8) | 2.5% | — | Pivotal Software Spring SecurityVmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+38 | 11/5/2018 | 25/8/2026 | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. |