CVE-2024-45073
- EPSS 0.23%
- Veröffentlicht 30.09.2024 22:15:02
- Zuletzt bearbeitet 07.01.2025 14:36:34
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr...
CVE-2023-50314
- EPSS 0.26%
- Veröffentlicht 14.08.2024 18:15:09
- Zuletzt bearbeitet 23.08.2024 19:20:22
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obta...
CVE-2023-50315
- EPSS 0.27%
- Veröffentlicht 14.08.2024 17:15:14
- Zuletzt bearbeitet 11.09.2024 13:38:26
IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive informati...
CVE-2024-35154
- EPSS 1.16%
- Veröffentlicht 09.07.2024 22:15:02
- Zuletzt bearbeitet 21.11.2024 09:19:50
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerabilit...
CVE-2024-35153
- EPSS 0.36%
- Veröffentlicht 27.06.2024 18:15:18
- Zuletzt bearbeitet 21.11.2024 09:19:49
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...
CVE-2024-37532
- EPSS 0.35%
- Veröffentlicht 20.06.2024 14:15:10
- Zuletzt bearbeitet 21.11.2024 09:24:01
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.
CVE-2024-25026
- EPSS 0.79%
- Veröffentlicht 25.04.2024 13:15:51
- Zuletzt bearbeitet 27.02.2025 16:24:20
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability...
CVE-2024-22329
- EPSS 0.3%
- Veröffentlicht 17.04.2024 02:15:10
- Zuletzt bearbeitet 06.03.2025 14:24:40
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerabilit...
- EPSS 0.65%
- Veröffentlicht 17.04.2024 01:15:06
- Zuletzt bearbeitet 06.03.2025 14:24:40
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerabil...
CVE-2024-27268
- EPSS 1.28%
- Veröffentlicht 04.04.2024 18:15:13
- Zuletzt bearbeitet 10.04.2025 21:05:27
IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources...