Show filters
71 Total Results
Displaying 41-50 of 71
Sort by:
Attacker Value
Unknown
CVE-2011-1314
Disclosure Date: March 08, 2011 (last updated October 04, 2023)
The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (daemon hang) by performing close operations via network connections to a queue manager.
0
Attacker Value
Unknown
CVE-2011-1318
Disclosure Date: March 08, 2011 (last updated October 04, 2023)
Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.
0
Attacker Value
Unknown
CVE-2011-1308
Disclosure Date: March 08, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-1317
Disclosure Date: March 08, 2011 (last updated October 04, 2023)
Memory leak in com.ibm.ws.jsp.runtime.WASJSPStrBufferImpl in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by sending many JSP requests that trigger large responses.
0
Attacker Value
Unknown
CVE-2011-1321
Disclosure Date: March 08, 2011 (last updated October 04, 2023)
The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 does not purge a user from the PlatformCredential cache, which might allow remote authenticated users to gain privileges by leveraging a group membership specified in an old RACF Object (aka RACO).
0
Attacker Value
Unknown
CVE-2011-1312
Disclosure Date: March 08, 2011 (last updated October 04, 2023)
The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.
0
Attacker Value
Unknown
CVE-2011-1309
Disclosure Date: March 08, 2011 (last updated October 04, 2023)
The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.
0
Attacker Value
Unknown
CVE-2011-1319
Disclosure Date: March 08, 2011 (last updated October 04, 2023)
The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote authenticated users to cause a denial of service (memory consumption) by using a Lightweight Third-Party Authentication (LTPA) token for authentication.
0
Attacker Value
Unknown
CVE-2011-1311
Disclosure Date: March 08, 2011 (last updated October 04, 2023)
The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow remote authenticated users to gain privileges in opportunistic circumstances by requesting a service.
0
Attacker Value
Unknown
CVE-2011-1315
Disclosure Date: March 08, 2011 (last updated October 04, 2023)
Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via network connections associated with a NULL return value from a synchronous JMS receive call.
0