Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2006-2436

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.
0
Attacker Value
Unknown

CVE-2006-2435

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
0
Attacker Value
Unknown

CVE-2006-1093

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive information via unknown attack vectors, which causes JSP source code to be revealed.
0
Attacker Value
Unknown

CVE-2005-4834

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and other sensitive information, related to incorrect request processing by the web container.
0
Attacker Value
Unknown

CVE-2005-3760

Disclosure Date: November 22, 2005 (last updated February 22, 2025)
Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allows attackers to cause a denial of service (ABEND).
0
Attacker Value
Unknown

CVE-2005-2091

Disclosure Date: July 05, 2005 (last updated February 22, 2025)
IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
0
Attacker Value
Unknown

CVE-2005-1872

Disclosure Date: June 03, 2005 (last updated February 22, 2025)
Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2005-0425

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.
0
Attacker Value
Unknown

CVE-2005-1112

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.
0