Show filters
432 Total Results
Displaying 11-20 of 432
Sort by:
Attacker Value
Unknown
CVE-2023-50315
Disclosure Date: August 14, 2024 (last updated September 12, 2024)
IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.
0
Attacker Value
Unknown
CVE-2024-35154
Disclosure Date: July 09, 2024 (last updated September 21, 2024)
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.
0
Attacker Value
Unknown
CVE-2024-35153
Disclosure Date: June 27, 2024 (last updated August 03, 2024)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 292640.
0
Attacker Value
Unknown
CVE-2024-37532
Disclosure Date: June 20, 2024 (last updated August 22, 2024)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.
0
Attacker Value
Unknown
CVE-2024-25026
Disclosure Date: April 25, 2024 (last updated April 26, 2024)
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 281516.
0
Attacker Value
Unknown
CVE-2024-22329
Disclosure Date: April 17, 2024 (last updated October 23, 2024)
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the SSRF attack. X-Force ID: 279951.
0
Attacker Value
Unknown
CVE-2024-22354
Disclosure Date: April 17, 2024 (last updated May 22, 2024)
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forgery attack. IBM X-Force ID: 280401.
0
Attacker Value
Unknown
CVE-2024-27268
Disclosure Date: April 04, 2024 (last updated May 16, 2024)
IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 284574.
0
Attacker Value
Unknown
CVE-2023-50313
Disclosure Date: April 02, 2024 (last updated April 09, 2024)
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274812.
0
Attacker Value
Unknown
CVE-2024-22353
Disclosure Date: March 31, 2024 (last updated May 16, 2024)
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 280400.
0