Web Servers Family for Nessus

IDNameSeverity
138762SAP NetWeaver : Authentication Bypass (CVE-2020-6287) (Direct Check)
critical
138591Apache Tomcat 9.0.0.M1 < 9.0.37 multiple vulnerabilities
high
138574Apache Tomcat 8.5.0 < 8.5.57 multiple vulnerabilities
high
138509Oracle WebLogic IIOP JNDI Lookup RCE Direct Check
critical
138506SAP NetWeaver AS Java Multiple Vulnerabilities
critical
138499SAP Netweaver Application Server (AS) HTTP Server Detection
info
138098Apache Tomcat 9.0.0.M1 < 9.0.36
high
138097Apache Tomcat 8.5.0 < 8.5.56
high
138091IBM WebSphere Application Server 7.0.0.x <= 7.0.0.45 / 8.0.0.x <= 8.0.0.15 / 8.5.x < 8.5.5.18 / 9.0.x < 9.0.5.5 Information Disclosure (CVE-2020-4449)
high
138074Oracle WebLogic Server Java Object Deserialization RCE (CVE-2020-2883)
critical
137398IBM WebSphere Application Server 7.0.0.x <= 7.0.0.45 / 8.0.0.x <= 8.0.0.15 / 8.5.x < 8.5.5.18 / 9.0.x < 9.0.5.4 Remote Code Execution (CVE-2020-4448)
critical
137368IBM WebSphere Application Server 8.5.x < 8.5.5.18 / 9.0.x < 9.0.5.5 RCE (CVE-2020-4450)
critical
136931Apache Traffic Server - HTTP Smuggling and Cache poisoning
medium
136897IBM WebSphere Application Server 7.0.0.0 <= 7.0.0.45 / 8.0.0.0 <= 8.0.0.15 / 8.5.0.0 <= 8.5.5.14 / 9.0.0.0 <= 9.0.0.9 XSS
medium
136892IBM WebSphere Application Server Admin Console 7.0.0.0 <= 7.0.0.45 / 8.0.0.0 <= 8.0.0.15 / 8.5.0.0 <= 8.5.5.14 / 9.0.0.0 <= 9.0.0.9 XSS
medium
136807Apache Tomcat 8.5.0 < 8.5.55
high
136806Apache Tomcat 9.0.0 < 9.0.35
high
136770Apache Tomcat 7.0.0 < 7.0.104
high
136764IBM MQ Console Detection
info
136763IBM MQ Default Credentials
critical
136426IBM WebSphere Application Server 9.0.0.0 < 9.0.0.9 Information Disclosure (CVE-2018-1957)
medium
136410IBM WebSphere Application Server 7.0 < 7.0.0.46 / 8.0 < 8.0.0.16 / 8.5 < 8.5.5.18 / 9.0 < 9.0.5.4 / Liberty 17.0.0.3 < 20.0.0.5 Information Disclosure
medium
136340nginx Installed (Linux/UNIX)
info
136183IBM WebSphere Application Server 7.0.0.0 <= 7.0.0.45 / 8.0.0.0 <= 8.0.0.15 / 8.5.0.0 <= 8.5.5.14 / 9.0.0.0 <= 9.0.0.9 Cross-Site Scripting Vulnerability
medium
136180IBM WebSphere Application Server 7.x / 8.0.0.0 <= 8.0.0.15 / 8.5.0.0 <= 8.5.5.14 / 9.0.0.0 <= 9.0.0.9 Directory Traversal Vulnerability
medium
135919OpenSSL 1.1.1d < 1.1.1g Vulnerability
high
135771IBM WebSphere Application Server 7.0.0.x <= 7.0.0.45 / 8.0.0.x <= 8.0.0.15 / 8.5.x < 8.5.5.15 / 9.x < 9.0.0.10 XSS (CVE-2018-1794)
medium
135720IBM WebSphere Application Server 7.0.0.0 <= 7.0.0.45 / 8.0.0.0 <= 8.0.0.15 / 8.5.0.0 <= 8.5.5.15 / 9.0.0.0 <= 9.0.0.10 Connection Spoofing Vulnerability
medium
135702IBM WebSphere Application Server 7.0.0.0 <= 7.0.0.45 / 8.0.0.0 <= 8.0.0.15 / 8.5.0.0 <= 8.5.5.17 / 9.0.0.0 <= 9.0.5.3 Privilege Escalation (CVE-2020-4362)
high
135677Oracle Fusion Middleware Oracle HTTP Server (Apr 2020 CPU)
high
135290Apache 2.4.x < 2.4.42 Multiple Vulnerabilities
medium
135180IBM WebSphere Application Server 7.0.0.x <= 7.0.0.45 / 8.0.0.x <= 8.0.0.15 / 8.5.x < 8.5.5.18 / 9.0.x < 9.0.5.4 Privilege Escalation (CVE-2020-4276)
high
134862Apache Tomcat AJP Connector Request Injection (Ghostcat)
critical
134220nginx < 1.17.7 Information Disclosure
medium
133845Apache Tomcat 9.0.0.M1 < 9.0.31 multiple vulnerabilities
critical
133696IBM WebSphere Application Server 7.0.0.x <= 7.0.0.45 / 8.0.0.x <= 8.0.0.15 / 8.5.x < 8.5.5.17 / 9.0.x < 9.0.5.3 Command Execution (CVE-2020-4163)
high
133529IBM WebSphere Application Server Denial of Service (CVE-2019-4720)
high
133360IBM WebSphere Application Server Virtual Enterprise 7.0.x <= 7.0.0.6 / Virtual Enterprise 8.0.x / 8.5.5.x < 8.5.5.17 / 9.0.x < 9.0.5.1 Information Disclosure (CVE-2019-4505)
medium
133275IBM WebSphere Application Server 9.0.x < 9.0.5.0 Information Disclosure (CVE-2019-4269)
high
133274IBM WebSphere Application Server 8.5.x < 8.5.5.15 / 9.0.0.x < 9.0.0.10 Cross-Site Request Forgery (CVE-2018-1926)
high
133273IBM WebSphere Application Server 8.5.x < 8.5.5.15 / 9.0.0.x < 9.0.0.10 Privilege Escalation (CVE-2018-1901)
high
133272IBM WebSphere Application Server 8.5.x < 8.5.5.15 / 9.0.0.x < 9.0.0.10 Privilege Escalation (CVE-2018-1840)
high
133271IBM WebSphere Application Server 8.5.x < 8.5.5.15 / 9.0.0.x < 9.0.0.10 Information Disclosure (CVE-2018-1614)
high
133270IBM WebSphere Application Server 7.0.0.x <= 7.0.0.45 / 8.0.0.x <= 8.0.0.15 / 8.5.x < 8.5.5.15 / 9.0.0.x < 9.0.0.10 Remote Code Execution (CVE-2018-1567)
critical
133146Oracle Fusion Middleware Oracle HTTP Server (Jan 2020 CPU)
medium
132775nginx 0.8.x < 0.8.33 / 0.7.x < 0.7.65 Windows Filename Pseudonyms (CORE-2010-0121)
low
132726OpenSSL 1.0.2 < 1.0.2u Vulnerability
medium
132725OpenSSL 1.1.1 < 1.1.1e-dev Procedure Overflow Vulnerability
medium
132419Apache Tomcat 9.0.0.M1 < 9.0.30
high
132418Apache Tomcat 8.5.0 < 8.5.50
high