Ibm Websphere Virtual Enterprise vulnerabilities

8 known vulnerabilities affecting ibm/websphere_virtual_enterprise.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM5LOW2

Vulnerabilities

Page 1 of 1
CVE-2020-4575MEDIUMCVSS 6.1v7.0v8.02020-08-27
CVE-2020-4575 [MEDIUM] CWE-79 CVE-2020-4575: IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 ar IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
cvelistv5nvd
CVE-2020-4448CRITICALCVSS 9.8v7.0v8.02020-06-05
CVE-2020-4448 [CRITICAL] CWE-502 CVE-2020-4448: IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote atta IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.
nvd
CVE-2019-4505MEDIUMCVSS 5.3v7.0v8.02019-09-20
CVE-2019-4505 [MEDIUM] CVE-2019-4505: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote atta IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL. This can lead the attacker to view any file in a certain directory. IBM X-Force ID: 164364.
nvd
CVE-2019-4030MEDIUMCVSS 5.4v7.0v8.02019-03-06
CVE-2019-4030 [MEDIUM] CWE-79 CVE-2019-4030: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155946.
nvd
CVE-2015-1932MEDIUMCVSS 5.0≤ 7.0.0.62015-08-22
CVE-2015-1932 [MEDIUM] CWE-200 CVE-2015-1932: IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5. IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
nvd
CVE-2015-1946MEDIUMCVSS 4.4v7.0v7.0.0.1+4 more2015-07-14
CVE-2015-1946 [MEDIUM] CWE-264 CVE-2015-1946: IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 befo IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2013-6323LOWCVSS 3.5v7.0v7.0.0.1+3 more2014-05-01
CVE-2013-6323 [LOW] CWE-79 CVE-2013-6323: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-5425LOWCVSS 3.5v6.1v6.1.1+9 more2013-11-18
CVE-2013-5425 [LOW] CWE-79 CVE-2013-5425: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Ente Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd