Show filters
118 Total Results
Displaying 91-100 of 118
Sort by:
Attacker Value
Unknown
CVE-2009-2085
Disclosure Date: August 13, 2009 (last updated October 04, 2023)
The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).
0
Attacker Value
Unknown
CVE-2009-0904
Disclosure Date: July 05, 2009 (last updated October 04, 2023)
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.
0
Attacker Value
Unknown
CVE-2009-0903
Disclosure Date: June 25, 2009 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.
0
Attacker Value
Unknown
CVE-2009-1008
Disclosure Date: April 15, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010.
0
Attacker Value
Unknown
CVE-2009-1010
Disclosure Date: April 15, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1008.
0
Attacker Value
Unknown
CVE-2009-1009
Disclosure Date: April 15, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML.
0
Attacker Value
Unknown
CVE-2009-1172
Disclosure Date: March 31, 2009 (last updated October 04, 2023)
The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2009-0892
Disclosure Date: March 31, 2009 (last updated October 04, 2023)
The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout.
0
Attacker Value
Unknown
CVE-2009-0891
Disclosure Date: March 25, 2009 (last updated October 04, 2023)
The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks.
0
Attacker Value
Unknown
CVE-2009-0508
Disclosure Date: March 16, 2009 (last updated October 04, 2023)
The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.
0