Show filters
125 Total Results
Displaying 111-120 of 125
Sort by:
Attacker Value
Unknown
CVE-2010-1651
Disclosure Date: May 03, 2010 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log.
0
Attacker Value
Unknown
CVE-2010-0768
Disclosure Date: April 01, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the URI.
0
Attacker Value
Unknown
CVE-2010-0769
Disclosure Date: April 01, 2010 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by reading a cleartext field in the resources.xml file.
0
Attacker Value
Unknown
CVE-2010-0770
Disclosure Date: April 01, 2010 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.
0
Attacker Value
Unknown
CVE-2010-1182
Disclosure Date: March 29, 2010 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2010-0563
Disclosure Date: February 08, 2010 (last updated October 04, 2023)
The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.
0
Attacker Value
Unknown
CVE-2009-2746
Disclosure Date: November 16, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-2743
Disclosure Date: September 21, 2009 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.
0
Attacker Value
Unknown
CVE-2009-2089
Disclosure Date: August 13, 2009 (last updated October 04, 2023)
The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by reading a Migration Trace file.
0
Attacker Value
Unknown
CVE-2009-2091
Disclosure Date: August 13, 2009 (last updated October 04, 2023)
The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new applications, which allows remote attackers to obtain sensitive information via unspecified vectors.
0