Show filters
133 Total Results
Displaying 11-20 of 133
Sort by:
Attacker Value
Unknown

CVE-2015-4938

Disclosure Date: August 22, 2015 (last updated October 05, 2023)
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-1932

Disclosure Date: August 22, 2015 (last updated October 05, 2023)
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
0
Attacker Value
Unknown

CVE-2015-1946

Disclosure Date: July 14, 2015 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-1927

Disclosure Date: July 14, 2015 (last updated October 05, 2023)
The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-1920

Disclosure Date: May 20, 2015 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.
0
Attacker Value
Unknown

CVE-2015-1885

Disclosure Date: April 27, 2015 (last updated October 05, 2023)
WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-6167

Disclosure Date: December 18, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown

CVE-2014-6174

Disclosure Date: December 18, 2014 (last updated October 05, 2023)
IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to conduct clickjacking attacks via a crafted web site.
0
Attacker Value
Unknown

CVE-2014-3021

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.
0
Attacker Value
Unknown

CVE-2014-4770

Disclosure Date: September 23, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.
0