CVE-2020-4575
- EPSS 0.13%
- Veröffentlicht 27.08.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:55
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
- EPSS 16.24%
- Veröffentlicht 05.06.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:32:45
IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.
CVE-2019-4505
- EPSS 0.19%
- Veröffentlicht 20.09.2019 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:43:40
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL. This can lead the attacker to view any file in a certain directory. I...
CVE-2019-4030
- EPSS 0.24%
- Veröffentlicht 06.03.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:43:03
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosur...
- EPSS 0.38%
- Veröffentlicht 22.08.2015 23:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software b...
CVE-2015-1946
- EPSS 0.06%
- Veröffentlicht 14.07.2015 17:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via...
CVE-2013-6323
- EPSS 0.29%
- Veröffentlicht 01.05.2014 17:29:56
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote aut...
CVE-2013-5425
- EPSS 0.19%
- Veröffentlicht 18.11.2013 03:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.