CVE-2012-2162
- EPSS 0.54%
- Published 01.05.2012 19:55:02
- Last modified 11.04.2025 00:51:21
The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the networ...
CVE-2012-0707
- EPSS 0.23%
- Published 23.02.2012 12:33:55
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach that is configured with a document attachment control section.
- EPSS 0.82%
- Published 20.01.2012 04:04:51
- Last modified 11.04.2025 00:51:21
IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allow...
CVE-2011-1376
- EPSS 0.04%
- Published 19.01.2012 11:55:10
- Last modified 11.04.2025 00:51:21
iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/isclite.ear/ and bin/client_ffdc/, which allows local users to read or m...
CVE-2011-5066
- EPSS 0.05%
- Published 15.01.2012 03:55:13
- Last modified 11.04.2025 00:51:21
The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (...
CVE-2011-1362
- EPSS 0.23%
- Published 15.01.2012 03:55:12
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrar...
- EPSS 1.37%
- Published 15.01.2012 03:55:12
- Last modified 11.04.2025 00:51:21
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack...
CVE-2011-5065
- EPSS 0.48%
- Published 15.01.2012 03:55:12
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.
- EPSS 0.21%
- Published 30.10.2011 10:55:02
- Last modified 11.04.2025 00:51:21
The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows re...
CVE-2009-2748
- EPSS 0.23%
- Published 30.10.2011 10:55:02
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.