CVE-2018-1444
- EPSS 0.32%
- Veröffentlicht 14.03.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:50
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t...
CVE-2018-1416
- EPSS 0.25%
- Veröffentlicht 27.02.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:46
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure...
CVE-2017-1761
- EPSS 0.28%
- Veröffentlicht 09.02.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:22:19
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure...
CVE-2018-1401
- EPSS 0.41%
- Veröffentlicht 09.02.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:45
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with...
CVE-2018-1361
- EPSS 0.41%
- Veröffentlicht 11.01.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:41
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t...
CVE-2017-1698
- EPSS 0.32%
- Veröffentlicht 27.12.2017 17:08:17
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390.
CVE-2017-1423
- EPSS 0.22%
- Veröffentlicht 20.12.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476.
CVE-2017-1536
- EPSS 0.25%
- Veröffentlicht 11.12.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially ...
CVE-2017-1577
- EPSS 1.47%
- Veröffentlicht 28.09.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X...
CVE-2017-1189
- EPSS 0.31%
- Veröffentlicht 07.09.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...