Show filters
432 Total Results
Displaying 321-330 of 432
Sort by:
Attacker Value
Unknown
CVE-2009-2090
Disclosure Date: August 13, 2009 (last updated October 04, 2023)
Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allows remote attackers to bypass intended Java Management Extensions (JMX) Management Beans (aka MBeans) access restrictions, and cause a denial of service (daemon stop), via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-0906
Disclosure Date: August 13, 2009 (last updated October 04, 2023)
The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-2092
Disclosure Date: August 13, 2009 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-0904
Disclosure Date: July 05, 2009 (last updated October 04, 2023)
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.
0
Attacker Value
Unknown
CVE-2009-0903
Disclosure Date: June 25, 2009 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.
0
Attacker Value
Unknown
CVE-2009-1898
Disclosure Date: June 03, 2009 (last updated October 04, 2023)
The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.
0
Attacker Value
Unknown
CVE-2009-1900
Disclosure Date: June 03, 2009 (last updated October 04, 2023)
The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool.
0
Attacker Value
Unknown
CVE-2009-1899
Disclosure Date: June 03, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticated users to obtain sensitive information via unknown use of the wsadmin scripting tool, related to a "security exposure in wsadmin."
0
Attacker Value
Unknown
CVE-2009-1901
Disclosure Date: June 03, 2009 (last updated October 04, 2023)
The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2009-0899
Disclosure Date: June 03, 2009 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors.
0