Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.806890
Kategorie:Web Servers
Titel:IBM Websphere Application Server Multiple Vulnerabilities-02 Mar16
Zusammenfassung:This host is installed with IBM Websphere; application server and is prone to multiple vulnerabilities.
Beschreibung:Summary:
This host is installed with IBM Websphere
application server and is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to improper
validation of input in the Administrative Console.

Vulnerability Impact:
Successful exploitation will allow a remote
attacker to obtain sensitive information, perform cross-site scripting attacks,
perform session injection and other malicious activities, also to inject script
into a victim's Web browser within the security context of the hosting Web site.

Affected Software/OS:
IBM WebSphere Application Server (WAS)
6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10,
and 8.5 before 8.5.5.4

Solution:
Upgrade to IBM WebSphere Application
Server (WAS) version 7.0.0.35, or 8.0.0.10, or 8.5.5.4, or later.
For version 6.1.0.47 and earlier 'Apply Interim Fix PI23055'

CVSS Score:
6.0

CVSS Vector:
AV:N/AC:M/Au:S/C:P/I:P/A:P

Querverweis: BugTraq ID: 69980
BugTraq ID: 69981
Common Vulnerability Exposure (CVE) ID: CVE-2014-4770
AIX APAR: PI23055
http://www-01.ibm.com/support/docview.wss?uid=swg1PI23055
http://www.securityfocus.com/bid/69981
CERT/CC vulnerability note: VU#573356
http://www.kb.cert.org/vuls/id/573356
http://secunia.com/advisories/61418
http://secunia.com/advisories/61423
XForce ISS Database: ibm-websphere-cve20144770-xss(95209)
https://exchange.xforce.ibmcloud.com/vulnerabilities/95209
Common Vulnerability Exposure (CVE) ID: CVE-2014-4816
http://www.securityfocus.com/bid/69980
XForce ISS Database: ibm-websphere-cve20144816-csrf(95402)
https://exchange.xforce.ibmcloud.com/vulnerabilities/95402
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.