Show filters
838 Total Results
Displaying 51-60 of 838
Sort by:
Attacker Value
Unknown

CVE-2021-39031

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.
Attacker Value
Unknown

CVE-2022-22310

Disclosure Date: January 18, 2022 (last updated October 07, 2023)
IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224.
Attacker Value
Unknown

CVE-2021-38951

Disclosure Date: December 08, 2021 (last updated October 07, 2023)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405.
Attacker Value
Unknown

CVE-2021-38949

Disclosure Date: November 15, 2021 (last updated February 23, 2025)
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.
Attacker Value
Unknown

CVE-2021-29842

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.
Attacker Value
Unknown

CVE-2021-29736

Disclosure Date: July 29, 2021 (last updated November 28, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.
Attacker Value
Unknown

CVE-2021-29754

Disclosure Date: June 10, 2021 (last updated November 28, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
Attacker Value
Unknown

CVE-2021-20517

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to read and delete arbitrary files on the system. IBM X-Force ID: 198435.
Attacker Value
Unknown

CVE-2021-20492

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.
Attacker Value
Unknown

CVE-2021-20454

Disclosure Date: April 20, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.