Show filters
838 Total Results
Displaying 11-20 of 838
Sort by:
Attacker Value
Unknown
CVE-2023-50314
Disclosure Date: August 14, 2024 (last updated August 24, 2024)
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274713.
0
Attacker Value
Unknown
CVE-2023-50315
Disclosure Date: August 14, 2024 (last updated September 12, 2024)
IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.
0
Attacker Value
Unknown
CVE-2024-35154
Disclosure Date: July 09, 2024 (last updated September 21, 2024)
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.
0
Attacker Value
Unknown
CVE-2024-35153
Disclosure Date: June 27, 2024 (last updated August 03, 2024)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 292640.
0
Attacker Value
Unknown
CVE-2024-37532
Disclosure Date: June 20, 2024 (last updated August 22, 2024)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.
0
Attacker Value
Unknown
CVE-2024-28764
Disclosure Date: May 01, 2024 (last updated May 02, 2024)
IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623.
0
Attacker Value
Unknown
CVE-2024-28775
Disclosure Date: May 01, 2024 (last updated May 02, 2024)
IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285648.
0
Attacker Value
Unknown
CVE-2024-25026
Disclosure Date: April 25, 2024 (last updated April 26, 2024)
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 281516.
0
Attacker Value
Unknown
CVE-2024-22329
Disclosure Date: April 17, 2024 (last updated October 23, 2024)
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the SSRF attack. X-Force ID: 279951.
0
Attacker Value
Unknown
CVE-2024-22354
Disclosure Date: April 17, 2024 (last updated May 22, 2024)
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forgery attack. IBM X-Force ID: 280401.
0