Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2780▲ 39 respecto a la semana anterior
Críticas / altas1283▼ 230 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

3 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.8%—IBM Iseries AS 4002/5/200516/6/2026
By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.
ModificadaMedia (5)1.7%—IBM Iseries AS 4002/5/200516/6/2026
The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.
ModificadaMedia (5)2.3%—IBM Iseries AS 4002/5/200516/6/2026
The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.
Orbitaley — Vulnerabilidades