Show filters
432 Total Results
Displaying 61-70 of 432
Sort by:
Attacker Value
Unknown

CVE-2020-4629

Disclosure Date: September 29, 2020 (last updated February 22, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.
Attacker Value
Unknown

CVE-2020-4643

Disclosure Date: September 17, 2020 (last updated February 22, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
Attacker Value
Unknown

CVE-2020-4590

Disclosure Date: September 16, 2020 (last updated October 07, 2023)
IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
Attacker Value
Unknown

CVE-2020-4578

Disclosure Date: September 09, 2020 (last updated February 22, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
Attacker Value
Unknown

CVE-2020-4575

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
Attacker Value
Unknown

CVE-2020-4589

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.
Attacker Value
Unknown

CVE-2020-4534

Disclosure Date: July 30, 2020 (last updated November 28, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges. IBM X-Force ID: 182808.
Attacker Value
Unknown

CVE-2020-4464

Disclosure Date: July 16, 2020 (last updated February 21, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.
Attacker Value
Unknown

CVE-2020-4450

Disclosure Date: June 04, 2020 (last updated February 21, 2025)
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
Attacker Value
Unknown

CVE-2020-4449

Disclosure Date: June 04, 2020 (last updated February 21, 2025)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181230.