Vulnerabilities > IBM > Websphere Virtual Enterprise > 7.0

DATE CVE VULNERABILITY TITLE RISK
2020-08-27 CVE-2020-4575 Cross-site Scripting vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
network
ibm CWE-79
4.3
2020-06-05 CVE-2020-4448 Deserialization of Untrusted Data vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources.
network
low complexity
ibm CWE-502
critical
10.0
2019-09-20 CVE-2019-4505 Unspecified vulnerability in IBM products
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL.
network
low complexity
ibm
5.3
2019-03-06 CVE-2019-4030 Cross-site Scripting vulnerability in IBM products
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2015-08-22 CVE-2015-1932 Information Exposure vulnerability in IBM products
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
network
low complexity
ibm CWE-200
5.0
2015-07-14 CVE-2015-1946 Permissions, Privileges, and Access Controls vulnerability in IBM products
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.
local
ibm CWE-264
4.4
2014-05-01 CVE-2013-6323 Cross-Site Scripting vulnerability in IBM products
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2013-11-18 CVE-2013-5425 Cross-Site Scripting vulnerability in IBM Websphere Virtual Enterprise
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5