Show filters
838 Total Results
Displaying 351-360 of 838
Sort by:
Attacker Value
Unknown

CVE-2015-1955

Disclosure Date: August 03, 2015 (last updated October 05, 2023)
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a crafted byte sequence in authentication data.
0
Attacker Value
Unknown

CVE-2015-1987

Disclosure Date: August 03, 2015 (last updated October 05, 2023)
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1958.
0
Attacker Value
Unknown

CVE-2015-1946

Disclosure Date: July 14, 2015 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-1936

Disclosure Date: July 14, 2015 (last updated October 05, 2023)
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
0
Attacker Value
Unknown

CVE-2015-1927

Disclosure Date: July 14, 2015 (last updated October 05, 2023)
The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-1887

Disclosure Date: July 14, 2015 (last updated October 05, 2023)
IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.
0
Attacker Value
Unknown

CVE-2015-1917

Disclosure Date: July 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown

CVE-2015-1944

Disclosure Date: July 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown

CVE-2015-1967

Disclosure Date: July 01, 2015 (last updated October 05, 2023)
MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which TLS is not used.
0
Attacker Value
Unknown

CVE-2015-0196

Disclosure Date: June 29, 2015 (last updated October 05, 2023)
CRLF injection vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 before 7.0.0.8 Cumulative iFix 2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
0