Nessus 的 Web Servers 系列

ID名稱嚴重性
339518OpenSSL 3.0.0 < 3.0.22 多個弱點
high
339490OpenSSL 3.4.0 < 3.4.7 多個弱點
high
339487OpenSSL 1.0.2 < 1.0.2zr 弱點
high
339486OpenSSL 1.1.1 < 1.1.1zi 多個弱點
high
339371Apache Tomcat 10.1.0.M1 < 10.1.59 多個弱點
medium
338327Grafana Labs 11.2.0 <= 11.6.16 / 12.2.0 <= 12.2.10 / 12.3.0 <= 12.3.8 / 12.4.0 <= 12.4.5 / 13.0.0 <= 13.0.3 / 13.1.0 < 13.1.1 資訊揭露 (CVE-2026-11817)
medium
337071IBM HTTP Server 8.5.x / 9.x Web Server Plug-in RCE (7274072)
critical
335451Azure CycleCloud 的安全性更新 < 8.9.1
critical
335450Azure CycleCloud < 8.9.2 的安全性更新 (2026 年 8 月)
high
335409SAP NetWeaver 記憶體損毀 (3756674)
medium
335408SAP NetWeaver AS Java易受攻擊的第三方元件 (3758318)
medium
335407SAP NetWeaver AS ABAP 缺少授權檢查 (3752864)
medium
335406SAP NetWeaver OS 命令插入 (3745182)
medium
335405SAP NetWeaver AS ABAP 權限提升 (3772411)
high
335404SAP NetWeaver 記憶體損毀 (3714806)
critical
335403SAP NetWeaver 作為 ABAP XSS (3721424)
medium
335167OpenSSL 3.5.0 < 3.5.8 多個弱點
high
335002IBM WebSphere Application Server Liberty 17.0.0.3 < 26.0.0.9 特權提升 (7283489)
high
335001IBM WebSphere Application Server Liberty 17.0.0.3 < 26.0.0.9 (7283488)
critical
335000IBM WebSphere Application Server Liberty 17.0.0.3 < 26.0.0.9 DoS (7283485)
medium
334999IBM WebSphere Application Server 9.x < 9.0.5.29 / Liberty 17.0.0.3 < 26.0.0.9 (7283567)
high
334516Apache Tomcat 9.0.13 < 9.0.117 插入敏感資訊弱點
high
334515Apache Tomcat 9.0.116 < 9.0.117 缺少敏感資料加密弱點 (CVE-2026-34486)
high
334514Apache Tomcat 9.0.40 < 9.0.117 不當編碼或逸出輸出弱點 (CVE-2026-34483)
high
333386IBM WebSphere eXtreme Scale < 8.6.2.08.6.2.2 (7282872)
high
333047IBM WebSphere Application Server 8.5.x < 8.5.5.31 / 9.x < 9.0.5.29 特權提升 (7281631)
critical
332717OpenSSL 3.6.0 < 3.6.4 多個弱點
high
332247IBM WebSphere Application Server 8.5.x < 8.5.5.31 / 9.x < 9.0.5.29 XSS (7281641)
critical
332244IBM WebSphere Application Server 8.5.x < 8.5.5.31 / 9.x < 9.0.5.29 (7281628)
critical
332232OpenSSL 4.0.0 < 4.0.2 多個弱點
high
330488IBM WebSphere Application Server 8.5.x < 8.5.5.31 / 9.x < 9.0.5.29 / Liberty 17.0.0.3 < 26.0.0.8 (7281625)
high
330487IBM WebSphere Application Server 8.5.x < 8.5.5.31 / 9.x < 9.0.5.29 (7281649)
high
330442Apache Tomcat 9.0.0.M1 < 9.0.121 多個弱點
critical
330425Apache Tomcat 11.0.0.M1 < 11.0.25 多個弱點
critical
330424Apache Tomcat 10.1.24 < 10.1.58
high
330305Oracle APEX (CVE-2026-60156) (2026 年 7 月 CPU)
medium
330304Oracle APEX (CVE-2026-54285) (2026 年 7 月 CPU)
medium
330303Oracle APEX (CVE-2026-60630) (2026 年 7 月 CPU)
medium
330084nginx 1.30.x < 1.30.4 / 1.31.2 < 1.31.3 -- 多個弱點
critical
329320Grafana Labs 12.4.0 < 12.4.4 / 13.0.0 < 13.0.2 多個弱點
medium
329319Grafana Labs < 11.6.15 / 12.2.0 < 12.2.9 / 12.3.0 < 12.3.7 / 12.4.0 < 12.4.4 / 13.0.0 < 13.0.2 多個弱點
medium
329200Oracle HTTP Server (2026 年 7 月 CPU)
critical
329199Oracle HTTP Server (2026 年 7 月 CPU)
critical
328876IBM WebSphere Application Server Liberty 17.0.0.3 < 26.0.0.8 DoS (7280126)
high
328875IBM WebSphere Application Server Liberty 17.0.0.3 < 26.0.0.8 DoS (7280695)
high
327605設定精靈中的 SAP NetWeaver AS Java XSS (3748227)
high
327604SAP NetWeaver AS ABAP BSP XSS (3754659)
medium
327603SAP NetWeaver AS ABAP 記憶體損毀 (3747367)
critical
327602SAP NetWeaver Enterprise Portal XSS (3746678)
medium
327109IBM WebSphere Application Server 8.5.x < 8.5.5.31 / 9.x < 9.0.5.29 / Liberty 17.0.0.3 < 26.0.0.8 (7280131)
high