CVE-2013-4053
- EPSS 1.26%
- Veröffentlicht 20.09.2013 21:55:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, when a trust store is configured...
CVE-2013-2967
- EPSS 2.1%
- Veröffentlicht 21.08.2013 21:55:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 allows remote attackers to inject arbitrary web scri...
CVE-2013-2976
- EPSS 0.35%
- Veröffentlicht 21.08.2013 21:55:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 does not properly perform caching, which allows local users to obtain sensitive information via ...
CVE-2013-3029
- EPSS 0.98%
- Veröffentlicht 21.08.2013 21:55:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote attackers to hijack the authent...
CVE-2013-4004
- EPSS 1.45%
- Veröffentlicht 21.08.2013 21:55:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.7 and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vector...
CVE-2013-4005
- EPSS 1.45%
- Veröffentlicht 21.08.2013 21:55:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrar...
CVE-2013-0597
- EPSS 1.45%
- Veröffentlicht 21.08.2013 21:55:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0, when OAuth is used, allows remote authenticated users to inject arbitrary web script or HTML via unspe...
- EPSS 9.81%
- Veröffentlicht 11.07.2013 22:55:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to exec...
CVE-2013-0482
- EPSS 2.03%
- Veröffentlicht 29.05.2013 14:29:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the sig...
CVE-2013-0540
- EPSS 1.6%
- Veröffentlicht 24.04.2013 10:28:37
- Zuletzt bearbeitet 29.04.2026 01:13:23
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.