Show filters
80 Total Results
Displaying 71-80 of 80
Sort by:
Attacker Value
Unknown
CVE-2012-3305
Disclosure Date: September 25, 2012 (last updated October 05, 2023)
Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.
0
Attacker Value
Unknown
CVE-2012-3325
Disclosure Date: August 30, 2012 (last updated October 05, 2023)
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote authenticated users to obtain administrative access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-2190
Disclosure Date: August 21, 2012 (last updated October 04, 2023)
IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of service (daemon crash) via a crafted ClientHello message in the TLS Handshake Protocol.
0
Attacker Value
Unknown
CVE-2012-3293
Disclosure Date: August 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a cross-frame scripting (XFS) issue.
0
Attacker Value
Unknown
CVE-2012-0193
Disclosure Date: January 20, 2012 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
0
Attacker Value
Unknown
CVE-2011-1368
Disclosure Date: October 29, 2011 (last updated October 04, 2023)
The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to read unspecified files via unknown vectors.
0
Attacker Value
Unknown
CVE-2011-1359
Disclosure Date: September 06, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
0
Attacker Value
Unknown
CVE-2009-1008
Disclosure Date: April 15, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010.
0
Attacker Value
Unknown
CVE-2009-1010
Disclosure Date: April 15, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1008.
0
Attacker Value
Unknown
CVE-2009-1009
Disclosure Date: April 15, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML.
0