Show filters
838 Total Results
Displaying 161-170 of 838
Sort by:
Attacker Value
Unknown
CVE-2018-1420
Disclosure Date: October 01, 2018 (last updated November 27, 2024)
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
0
Attacker Value
Unknown
CVE-2018-1716
Disclosure Date: September 27, 2018 (last updated November 27, 2024)
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147164.
0
Attacker Value
Unknown
CVE-2018-1736
Disclosure Date: September 27, 2018 (last updated November 27, 2024)
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 147906.
0
Attacker Value
Unknown
CVE-2018-1660
Disclosure Date: September 27, 2018 (last updated November 27, 2024)
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144886.
0
Attacker Value
Unknown
CVE-2018-1820
Disclosure Date: September 27, 2018 (last updated November 27, 2024)
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150096.
0
Attacker Value
Unknown
CVE-2018-1683
Disclosure Date: September 26, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455.
0
Attacker Value
Unknown
CVE-2018-1719
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to perform man-in-the-middle attacks. IBM X-Force ID: 147292.
0
Attacker Value
Unknown
CVE-2018-1567
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024.
0
Attacker Value
Unknown
CVE-2018-1695
Disclosure Date: September 06, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769.
0
Attacker Value
Unknown
CVE-2018-1644
Disclosure Date: August 27, 2018 (last updated November 27, 2024)
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenticated user to obtain sensitive information about another user.
0