Show filters
432 Total Results
Displaying 231-240 of 432
Sort by:
Attacker Value
Unknown
CVE-2012-5955
Disclosure Date: December 20, 2012 (last updated October 05, 2023)
Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown vectors.
0
Attacker Value
Unknown
CVE-2012-4851
Disclosure Date: November 14, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
0
Attacker Value
Unknown
CVE-2012-3330
Disclosure Date: November 14, 2012 (last updated October 05, 2023)
The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterprise, allows remote attackers to cause a denial of service (daemon outage) via a crafted request.
0
Attacker Value
Unknown
CVE-2012-4853
Disclosure Date: November 14, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger information disclosure.
0
Attacker Value
Unknown
CVE-2012-4850
Disclosure Date: November 14, 2012 (last updated October 05, 2023)
IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote attackers to gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-3306
Disclosure Date: September 25, 2012 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2012-3311
Disclosure Date: September 25, 2012 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-3304
Disclosure Date: September 25, 2012 (last updated October 05, 2023)
The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-3305
Disclosure Date: September 25, 2012 (last updated October 05, 2023)
Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.
0
Attacker Value
Unknown
CVE-2012-3325
Disclosure Date: August 30, 2012 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote authenticated users to obtain administrative access via unspecified vectors.
0