Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2012-09-25 CVE-2012-3306 Credentials Management vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.
network
ibm CWE-255
6.8
2012-09-25 CVE-2012-3305 Path Traversal vulnerability in IBM Websphere Application Server
Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.
network
low complexity
ibm CWE-22
6.4
2012-09-25 CVE-2012-3304 Unspecified vulnerability in IBM Websphere Application Server
The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.
network
ibm
6.8
2012-09-25 CVE-2012-3300 Resource Management Errors vulnerability in IBM Websphere Commerce
IBM WebSphere Commerce 7.0 before 7.0.0.6, when persistent sessions and personalization IDs are enabled, allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.
network
high complexity
ibm CWE-399
2.6
2012-09-25 CVE-2012-3298 Denial-Of-Service vulnerability in IBM Websphere Commerce 7.0
Unspecified vulnerability in the REST services framework in IBM WebSphere Commerce 7.0 Feature Pack 4 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.
network
low complexity
ibm
critical
10.0
2012-09-25 CVE-2012-2199 Resource Management Errors vulnerability in IBM Websphere MQ
The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote attackers to cause a denial of service (invalid address alignment exception and daemon crash) via vectors involving a multiplexed channel.
network
low complexity
ibm oracle CWE-399
5.0
2012-09-25 CVE-2012-2187 Cryptographic Issues vulnerability in IBM Remote Supervisor Adapter II Firmware
IBM Remote Supervisor Adapter II firmware for System x3650, x3850 M2, and x3950 M2 1.13 and earlier generates weak RSA keys, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.
network
low complexity
ibm CWE-310
5.0
2012-09-25 CVE-2012-4015 Cross-Site Scripting vulnerability in Mylittletools Mylittleadmin
Cross-site scripting (XSS) vulnerability in the management screen in myLittleTools myLittleAdmin for SQL Server 2000 allows remote attackers to inject arbitrary web script or HTML via vectors that trigger a crafted database entry.
4.3
2012-09-25 CVE-2012-4014 Denial of Service vulnerability in McAfee Email Anti-virus
Unspecified vulnerability in McAfee Email Anti-virus (formerly WebShield SMTP) allows remote attackers to cause a denial of service via unknown vectors.
network
low complexity
mcafee
7.8
2012-09-25 CVE-2012-3264 Unspecified vulnerability in HP Sitescope 11.10/11.11/11.12
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1472.
network
low complexity
hp
7.5