Show filters
838 Total Results
Displaying 141-150 of 838
Sort by:
Attacker Value
Unknown

CVE-2018-1957

Disclosure Date: December 10, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.
0
Attacker Value
Unknown

CVE-2018-1840

Disclosure Date: December 03, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
0
Attacker Value
Unknown

CVE-2017-1418

Disclosure Date: November 26, 2018 (last updated November 27, 2024)
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete these files with an unknown impact. IBM X-Force ID: 127406.
0
Attacker Value
Unknown

CVE-2018-1905

Disclosure Date: November 26, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152534.
0
Attacker Value
Unknown

CVE-2018-1797

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an attacker could exploit this vulnerability to write to arbitrary files on the system. Note: This vulnerability is known as "Zip-Slip". IBM X-Force ID: 149427.
0
Attacker Value
Unknown

CVE-2018-1643

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144588
0
Attacker Value
Unknown

CVE-2018-1792

Disclosure Date: November 13, 2018 (last updated November 27, 2024)
IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that could be executed with root privileges. IBM X-Force ID: 148947.
0
Attacker Value
Unknown

CVE-2018-1808

Disclosure Date: November 13, 2018 (last updated November 27, 2024)
IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input control. IBM X-Force ID: 149828.
0
Attacker Value
Unknown

CVE-2018-1798

Disclosure Date: November 12, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149428.
0
Attacker Value
Unknown

CVE-2018-1684

Disclosure Date: November 09, 2018 (last updated November 27, 2024)
IBM WebSphere MQ 8.0 through 9.1 is vulnerable to a error with MQTT topic string publishing that can cause a denial of service attack. IBM X-Force ID: 145456.
0