CVEs (465)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Websphere Application Server Nov 21, 2024 Dec 3, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Nov 26, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Nov 16, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Nov 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Nov 12, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pot...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service,...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 29, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended func...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 16, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pot...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811. |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 3, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended f...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Oct 3, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fu...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Sep 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455. |
1Ibm 1Websphere Application Server Nov 21, 2024 Sep 14, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to p...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Sep 7, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024. |
1Ibm 1Websphere Application Server Nov 21, 2024 Sep 6, 2018 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769. |
1Ibm 1Websphere Application Server Nov 21, 2024 Aug 24, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (J...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Jul 6, 2018 N/A· v4 6.7 MEDIUM· v3 2.1 LOW· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346. |
1Ibm 1Websphere Application Server Nov 21, 2024 Jun 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890. |
1Ibm 1Websphere Application Server Nov 21, 2024 Jun 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information. IBM X-Force ID: 144270. |