Show filters
71 Total Results
Displaying 31-40 of 71
Sort by:
Attacker Value
Unknown
CVE-2011-1362
Disclosure Date: January 15, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1308.
0
Attacker Value
Unknown
CVE-2011-1377
Disclosure Date: January 15, 2012 (last updated October 04, 2023)
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.
0
Attacker Value
Unknown
CVE-2011-5065
Disclosure Date: January 15, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.
0
Attacker Value
Unknown
CVE-2011-5066
Disclosure Date: January 15, 2012 (last updated October 04, 2023)
The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (FFDC) introspection code, which allows local users to obtain sensitive information by reading the FFDC log file.
0
Attacker Value
Unknown
CVE-2011-1359
Disclosure Date: September 06, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
0
Attacker Value
Unknown
CVE-2011-1356
Disclosure Date: July 19, 2011 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Console request.
0
Attacker Value
Unknown
CVE-2011-1355
Disclosure Date: July 19, 2011 (last updated October 04, 2023)
Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage parameter.
0
Attacker Value
Unknown
CVE-2010-3271
Disclosure Date: July 18, 2011 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.
0
Attacker Value
Unknown
CVE-2011-1209
Disclosure Date: May 04, 2011 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Security XML encryption algorithm, which makes it easier for remote attackers to obtain plaintext data from a (1) JAX-RPC or (2) JAX-WS Web Services request via unspecified vectors related to a "decryption attack."
0
Attacker Value
Unknown
CVE-2011-1683
Disclosure Date: April 13, 2011 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registry or Federated Repository with RACF adapter is used, allows remote attackers to obtain unspecified application access via unknown vectors.
0