Show filters
97 Total Results
Displaying 51-60 of 97
Sort by:
Attacker Value
Unknown

CVE-2012-0717

Disclosure Date: June 20, 2012 (last updated October 04, 2023)
IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client authentication is used, allows remote attackers to bypass X.509 client-certificate authentication via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-2162

Disclosure Date: May 01, 2012 (last updated October 04, 2023)
The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.
0
Attacker Value
Unknown

CVE-2011-1362

Disclosure Date: January 15, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1308.
0
Attacker Value
Unknown

CVE-2009-2747

Disclosure Date: October 30, 2011 (last updated October 04, 2023)
The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.
0
Attacker Value
Unknown

CVE-2009-2748

Disclosure Date: October 30, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-1359

Disclosure Date: September 06, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
0
Attacker Value
Unknown

CVE-2011-1356

Disclosure Date: July 19, 2011 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Console request.
0
Attacker Value
Unknown

CVE-2011-1355

Disclosure Date: July 19, 2011 (last updated October 04, 2023)
Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage parameter.
0
Attacker Value
Unknown

CVE-2010-3271

Disclosure Date: July 18, 2011 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.
0
Attacker Value
Unknown

CVE-2011-1209

Disclosure Date: May 04, 2011 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Security XML encryption algorithm, which makes it easier for remote attackers to obtain plaintext data from a (1) JAX-RPC or (2) JAX-WS Web Services request via unspecified vectors related to a "decryption attack."
0