CVE-2020-4534
- EPSS 0.07%
- Veröffentlicht 03.08.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:32:51
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacke...
- EPSS 45.41%
- Veröffentlicht 17.07.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:32:46
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.
- EPSS 16.24%
- Veröffentlicht 05.06.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:32:45
IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.
CVE-2020-4449
- EPSS 0.57%
- Veröffentlicht 05.06.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:32:45
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181230.
- EPSS 71.86%
- Veröffentlicht 05.06.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:32:45
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
CVE-2020-4365
- EPSS 0.09%
- Veröffentlicht 14.05.2020 16:15:15
- Zuletzt bearbeitet 21.11.2024 05:32:39
IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.
CVE-2020-10693
- EPSS 0.29%
- Veröffentlicht 06.05.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:55:52
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping...
CVE-2020-4421
- EPSS 0.17%
- Veröffentlicht 06.05.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:43
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
CVE-2020-4329
- EPSS 0.21%
- Veröffentlicht 28.04.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:32:36
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenticated attacker to obtain sensitive information, caused by improper parameter checking. This could be exploited to conduct spoofing...
CVE-2020-4362
- EPSS 0.53%
- Veröffentlicht 10.04.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:38
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.