Show filters
432 Total Results
Displaying 421-430 of 432
Sort by:
Attacker Value
Unknown
CVE-2003-1447
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
0
Attacker Value
Unknown
CVE-2002-1153
Disclosure Date: October 11, 2002 (last updated February 22, 2025)
IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".
0
Attacker Value
Unknown
CVE-2001-1189
Disclosure Date: December 13, 2001 (last updated February 22, 2025)
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
0
Attacker Value
Unknown
CVE-2001-0824
Disclosure Date: December 06, 2001 (last updated February 22, 2025)
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
0
Attacker Value
Unknown
CVE-2001-0962
Disclosure Date: September 19, 2001 (last updated February 22, 2025)
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
0
Attacker Value
Unknown
CVE-2001-0389
Disclosure Date: July 02, 2001 (last updated February 22, 2025)
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
0
Attacker Value
Unknown
CVE-2001-0390
Disclosure Date: July 02, 2001 (last updated February 22, 2025)
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
0
Attacker Value
Unknown
CVE-2001-0122
Disclosure Date: March 13, 2001 (last updated February 22, 2025)
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
0
Attacker Value
Unknown
CVE-2000-0848
Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
0
Attacker Value
Unknown
CVE-2000-0652
Disclosure Date: July 24, 2000 (last updated February 22, 2025)
IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.
0