Show filters
88 Total Results
Displaying 81-88 of 88
Sort by:
Attacker Value
Unknown
CVE-2009-2743
Disclosure Date: September 21, 2009 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.
0
Attacker Value
Unknown
CVE-2009-2744
Disclosure Date: September 21, 2009 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25."
0
Attacker Value
Unknown
CVE-2009-2089
Disclosure Date: August 13, 2009 (last updated October 04, 2023)
The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by reading a Migration Trace file.
0
Attacker Value
Unknown
CVE-2009-2088
Disclosure Date: August 13, 2009 (last updated October 04, 2023)
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass authentication via a request for a "secure URL," related to a certain invokefilterscompatibility property.
0
Attacker Value
Unknown
CVE-2009-2087
Disclosure Date: August 13, 2009 (last updated October 04, 2023)
The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfuscation, which allows local users to cause a denial of service (deployment failure) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-2085
Disclosure Date: August 13, 2009 (last updated October 04, 2023)
The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).
0
Attacker Value
Unknown
CVE-2009-0904
Disclosure Date: July 05, 2009 (last updated October 04, 2023)
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.
0
Attacker Value
Unknown
CVE-2009-0903
Disclosure Date: June 25, 2009 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.
0