Show filters
432 Total Results
Displaying 401-410 of 432
Sort by:
Attacker Value
Unknown

CVE-2006-2432

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
0
Attacker Value
Unknown

CVE-2006-2429

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".
0
Attacker Value
Unknown

CVE-2006-2433

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".
0
Attacker Value
Unknown

CVE-2006-2431

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.
0
Attacker Value
Unknown

CVE-2006-2430

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
0
Attacker Value
Unknown

CVE-2006-2434

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.
0
Attacker Value
Unknown

CVE-2006-2436

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.
0
Attacker Value
Unknown

CVE-2006-2435

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
0
Attacker Value
Unknown

CVE-2006-2342

Disclosure Date: May 12, 2006 (last updated October 04, 2023)
IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.
0
Attacker Value
Unknown

CVE-2006-1619

Disclosure Date: April 05, 2006 (last updated February 22, 2025)
IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header.
0