Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2006-3232

Disclosure Date: June 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."
0
Attacker Value
Unknown

CVE-2006-3231

Disclosure Date: June 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."
0
Attacker Value
Unknown

CVE-2001-1189

Disclosure Date: December 13, 2001 (last updated February 22, 2025)
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
0
Attacker Value
Unknown

CVE-2001-0824

Disclosure Date: December 06, 2001 (last updated February 22, 2025)
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
0
Attacker Value
Unknown

CVE-2000-0848

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
0
Attacker Value
Unknown

CVE-2000-0652

Disclosure Date: July 24, 2000 (last updated February 22, 2025)
IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.
0
Attacker Value
Unknown

CVE-2000-0497

Disclosure Date: June 08, 2000 (last updated February 22, 2025)
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.