Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown
CVE-2008-4284
Disclosure Date: February 10, 2009 (last updated October 04, 2023)
Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before 6.1.0.23 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage feature.
0
Attacker Value
Unknown
CVE-2008-4283
Disclosure Date: February 10, 2009 (last updated October 04, 2023)
CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-2221
Disclosure Date: May 14, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2006-7164
Disclosure Date: March 20, 2007 (last updated October 04, 2023)
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.
0
Attacker Value
Unknown
CVE-2006-7166
Disclosure Date: March 20, 2007 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a specific JSP URL."
0
Attacker Value
Unknown
CVE-2006-3232
Disclosure Date: June 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."
0
Attacker Value
Unknown
CVE-2006-3231
Disclosure Date: June 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."
0
Attacker Value
Unknown
CVE-2006-2432
Disclosure Date: May 17, 2006 (last updated October 04, 2023)
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
0
Attacker Value
Unknown
CVE-2006-2431
Disclosure Date: May 17, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.
0
Attacker Value
Unknown
CVE-2006-2430
Disclosure Date: May 17, 2006 (last updated October 04, 2023)
IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
0