Show filters
432 Total Results
Displaying 51-60 of 432
Sort by:
Attacker Value
Unknown

CVE-2021-20492

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.
Attacker Value
Unknown

CVE-2021-20454

Disclosure Date: April 20, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.
Attacker Value
Unknown

CVE-2021-20453

Disclosure Date: April 19, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648.
Attacker Value
Unknown

CVE-2021-20480

Disclosure Date: April 07, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502.
Attacker Value
Unknown

CVE-2020-5016

Disclosure Date: March 09, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When application security is disabled and JAX-RPC applications are present, an attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary xml files on the system. This does not occur if Application security is enabled. IBM X-Force ID: 193556.
Attacker Value
Unknown

CVE-2021-20354

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
Attacker Value
Unknown

CVE-2021-20353

Disclosure Date: February 09, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.
Attacker Value
Unknown

CVE-2020-4949

Disclosure Date: January 25, 2021 (last updated February 22, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
Attacker Value
Unknown

CVE-2020-4782

Disclosure Date: October 27, 2020 (last updated February 22, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Attacker Value
Unknown

CVE-2020-4576

Disclosure Date: September 30, 2020 (last updated November 28, 2024)
IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 184428.