Show filters
838 Total Results
Displaying 161-170 of 838
Sort by:
Attacker Value
Unknown

CVE-2018-1420

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
0
Attacker Value
Unknown

CVE-2018-1716

Disclosure Date: September 27, 2018 (last updated November 27, 2024)
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147164.
0
Attacker Value
Unknown

CVE-2018-1736

Disclosure Date: September 27, 2018 (last updated November 27, 2024)
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 147906.
0
Attacker Value
Unknown

CVE-2018-1660

Disclosure Date: September 27, 2018 (last updated November 27, 2024)
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144886.
0
Attacker Value
Unknown

CVE-2018-1820

Disclosure Date: September 27, 2018 (last updated November 27, 2024)
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150096.
0
Attacker Value
Unknown

CVE-2018-1683

Disclosure Date: September 26, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455.
0
Attacker Value
Unknown

CVE-2018-1719

Disclosure Date: September 14, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to perform man-in-the-middle attacks. IBM X-Force ID: 147292.
0
Attacker Value
Unknown

CVE-2018-1567

Disclosure Date: September 07, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024.
0
Attacker Value
Unknown

CVE-2018-1695

Disclosure Date: September 06, 2018 (last updated November 27, 2024)
IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769.
0
Attacker Value
Unknown

CVE-2018-1644

Disclosure Date: August 27, 2018 (last updated November 27, 2024)
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenticated user to obtain sensitive information about another user.
0