CVE Vulnerabilities for "product:hp-ux"

Showing 1-10 of 485 CVEs (filtered from 316,527 total)

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.

MEDIUM 5.3
EPSS 0.0%
8/14/2025
2025

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.

CRITICAL 9
EPSS 0.3%
6/25/2025
2025

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

MEDIUM 4.4
EPSS 0.0%
5/14/2025
2025

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

MEDIUM 4.1
EPSS 0.0%
4/22/2025
2025

IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0.0 through 8.1.23.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

MEDIUM 5.9
EPSS 0.0%
1/27/2025
2024

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query.

MEDIUM 5.3
EPSS 0.1%
12/19/2024
2023

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

MEDIUM 5.5
EPSS 0.1%
10/16/2024
2024

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

MEDIUM 5.5
EPSS 0.1%
10/16/2024
2024

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

MEDIUM 4.8
EPSS 0.1%
9/30/2024
2024

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 283813.

MEDIUM 5.3
EPSS 0.1%
4/3/2024
2024
Page 1 of 2