VendorsHPhp-uxany version
Vulnerabilities

HP -UX family of operating systems any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

187CVEs
CVE-2016-8966
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Published 2017-02-01 · Modified
5.9EPSS 0.012
CVE-2019-4102
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.
Published 2019-07-01 · Modified
5.9EPSS 0.012
CVE-2022-38712
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762."
Published 2022-11-03 · Modified
5.9EPSS 0.005
CVE-2007-1898
formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.
Published 2007-05-16 · Modified
5.81 PoCEPSS 0.025
CVE-2008-0709
Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to access other user accounts via unknown vectors, a different issue than CVE-2008-0214.
Published 2008-04-07 · Modified
5.5EPSS 0.013
CVE-2024-45072
IBM WebSphere Application Server XML external entity injection
Published 2024-10-16 · Analyzed
5.5EPSS 0.004
CVE-2016-0371
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.
Published 2017-02-01 · Modified
5.5EPSS 0.003
CVE-2016-8981
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
Published 2017-02-01 · Modified
5.5EPSS 0.003
CVE-2021-38926
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.
Published 2021-12-09 · Modified
5.5EPSS 0.003
CVE-2019-4719
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data.
Published 2020-03-16 · Modified
5.5EPSS 0.003
CVE-2019-4619
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 168862.
Published 2020-03-16 · Modified
5.5EPSS 0.003
CVE-2016-8967
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
Published 2017-02-01 · Modified
5.5EPSS 0.003
CVE-2016-8963
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
Published 2017-02-01 · Modified
5.5EPSS 0.003
CVE-2024-45071
IBM WebSphere Application Server cross-site scripting
Published 2024-10-16 · Analyzed
5.5EPSS 0.002
CVE-2023-30903
HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6.
Published 2023-06-16 · Modified
5.5EPSS 0.002
CVE-2023-28950
IBM MQ information disclosure
Published 2023-05-19 · Modified
5.5EPSS 0.002
CVE-2021-20562
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199232.
Published 2021-07-27 · Modified
5.4EPSS 0.009
CVE-2020-4578
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
Published 2020-09-10 · Modified
5.4EPSS 0.007
CVE-2021-20560
IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 199229.
Published 2021-07-26 · Modified
5.4EPSS 0.006
CVE-2022-34165
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID: 229429.
Published 2022-09-09 · Modified
5.4EPSS 0.006
CVE-2023-33846
IBM CICS TX cross-site scripting
Published 2023-06-08 · Modified
5.4EPSS 0.005
CVE-2021-39035
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213965.
Published 2022-08-16 · Modified
5.4EPSS 0.005
CVE-2022-34336
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714.
Published 2022-09-13 · Modified
5.4EPSS 0.005
CVE-2023-42029
IBM CICS TX cross-site scripting
Published 2023-11-02 · Modified
5.4EPSS 0.004
CVE-2022-40750
IBM WebSphere Application Server cross-site scripting
Published 2022-11-11 · Modified
5.4EPSS 0.004
CVE-2023-26283
IBM WebSphere Application Server cross-site scripting
Published 2023-03-22 · Modified
5.4EPSS 0.004
CVE-2020-4365
IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.
Published 2020-05-14 · Modified
5.3EPSS 0.014
CVE-2020-4761
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 188895.
Published 2021-01-05 · Modified
5.3EPSS 0.013
CVE-2016-8977
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.
Published 2017-02-01 · Modified
5.3EPSS 0.011
CVE-2022-22473
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force ID: 225347.
Published 2022-07-14 · Modified
5.3EPSS 0.011
CVE-2021-39086
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889.
Published 2022-08-16 · Modified
5.3EPSS 0.009
CVE-2023-45177
IBM MQ denial of service
Published 2024-03-20 · Analyzed
5.3EPSS 0.006
CVE-2019-4236
A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve the object with incorrect ACL entries. IBM X-Force ID: 159418.
Published 2019-07-22 · Modified
5.1EPSS 0.003
CVE-1999-0104
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
Published 2000-02-04 · Modified
5.0EPSS 0.093
CVE-2007-1918
The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
5.0EPSS 0.025
CVE-1999-0312
HP ypbind allows attackers with root privileges to modify NIS data.
Published 1999-09-29 · Modified
5.0EPSS 0.025
CVE-2007-1913
The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
5.0EPSS 0.022
CVE-2001-0106
Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the "swait" state is used by a server.
Published 2001-05-07 · Modified
5.0EPSS 0.018
CVE-2007-3044
Unspecified vulnerability in the Map I/O Service (xpwmap) in Hitachi XP/W on HI-UX/WE2 before 20070319, and XP/W on HP-UX before 20070405, allows remote attackers to cause a denial of service via certain data to the service port.
Published 2007-06-05 · Modified
5.0EPSS 0.017
CVE-2007-3045
Unspecified vulnerability in Hitachi TP1/NET/OSI-TP-Extended on HI-UX/WE2 before 20070213, and on HP-UX before 20070314, allows remote attackers to cause a denial of service via certain data to a port.
Published 2007-06-05 · Modified
5.0EPSS 0.014
← Prev4 / 5Next →