Show filters
838 Total Results
Displaying 351-360 of 838
Sort by:
Attacker Value
Unknown
CVE-2015-1955
Disclosure Date: August 03, 2015 (last updated October 05, 2023)
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a crafted byte sequence in authentication data.
0
Attacker Value
Unknown
CVE-2015-1987
Disclosure Date: August 03, 2015 (last updated October 05, 2023)
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1958.
0
Attacker Value
Unknown
CVE-2015-1946
Disclosure Date: July 14, 2015 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-1936
Disclosure Date: July 14, 2015 (last updated October 05, 2023)
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
0
Attacker Value
Unknown
CVE-2015-1927
Disclosure Date: July 14, 2015 (last updated October 05, 2023)
The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-1887
Disclosure Date: July 14, 2015 (last updated October 05, 2023)
IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.
0
Attacker Value
Unknown
CVE-2015-1917
Disclosure Date: July 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown
CVE-2015-1944
Disclosure Date: July 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown
CVE-2015-1967
Disclosure Date: July 01, 2015 (last updated October 05, 2023)
MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which TLS is not used.
0
Attacker Value
Unknown
CVE-2015-0196
Disclosure Date: June 29, 2015 (last updated October 05, 2023)
CRLF injection vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 before 7.0.0.8 Cumulative iFix 2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
0