Show filters
432 Total Results
Displaying 71-80 of 432
Sort by:
Attacker Value
Unknown
CVE-2020-4448
Disclosure Date: June 04, 2020 (last updated February 21, 2025)
IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.
0
Attacker Value
Unknown
CVE-2020-4365
Disclosure Date: May 13, 2020 (last updated February 21, 2025)
IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.
0
Attacker Value
Unknown
CVE-2020-10693
Disclosure Date: May 06, 2020 (last updated February 21, 2025)
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
0
Attacker Value
Unknown
CVE-2020-4421
Disclosure Date: May 05, 2020 (last updated February 21, 2025)
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
0
Attacker Value
Unknown
CVE-2020-4329
Disclosure Date: April 27, 2020 (last updated November 27, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenticated attacker to obtain sensitive information, caused by improper parameter checking. This could be exploited to conduct spoofing attacks. IBM X-Force ID: 177841.
0
Attacker Value
Unknown
CVE-2020-4362
Disclosure Date: April 09, 2020 (last updated November 27, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.
0
Attacker Value
Unknown
CVE-2020-4304
Disclosure Date: March 31, 2020 (last updated February 21, 2025)
IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176670.
0
Attacker Value
Unknown
CVE-2020-4303
Disclosure Date: March 31, 2020 (last updated February 21, 2025)
IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176668.
0
Attacker Value
Unknown
CVE-2020-4276
Disclosure Date: March 25, 2020 (last updated November 27, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.
0
Attacker Value
Unknown
CVE-2019-4670
Disclosure Date: February 04, 2020 (last updated November 27, 2024)
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper data representation. IBM X-Force ID: 171319.
0