Show filters
113 Total Results
Displaying 111-113 of 113
Sort by:
Attacker Value
Unknown

CVE-2010-0563

Disclosure Date: February 08, 2010 (last updated October 04, 2023)
The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.
0
Attacker Value
Unknown

CVE-2009-2746

Disclosure Date: November 16, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-2743

Disclosure Date: September 21, 2009 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.
0