CVE-2010-2327
- EPSS 0.76%
- Published 18.06.2010 18:30:01
- Last modified 11.04.2025 00:51:21
mod_ibm_ssl in IBM HTTP Server 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11, as used in IBM WebSphere Application Server (WAS) on z/OS, does not properly handle a large HTTP request body in uploading over SSL, which might allow r...
- EPSS 0.53%
- Published 18.06.2010 18:30:01
- Last modified 11.04.2025 00:51:21
The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (NullPointerException) via a large amount of chunked data that uses gzip compression.
CVE-2010-0774
- EPSS 0.14%
- Published 17.05.2010 22:30:01
- Last modified 11.04.2025 00:51:21
The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 do not properly handle WebServices PKCS#7 and PKIPath tokens, which all...
- EPSS 0.53%
- Published 17.05.2010 22:30:01
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a crafted request, re...
- EPSS 0.53%
- Published 17.05.2010 22:30:01
- Last modified 11.04.2025 00:51:21
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle chunked transfer encoding during a call to response.sendRedirect, which allows remote attackers to ...
CVE-2010-0777
- EPSS 0.55%
- Published 17.05.2010 22:30:01
- Last modified 11.04.2025 00:51:21
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote atta...
CVE-2010-1650
- EPSS 0.07%
- Published 03.05.2010 13:51:52
- Last modified 11.04.2025 00:51:21
IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified obj...
CVE-2010-1651
- EPSS 0.05%
- Published 03.05.2010 13:51:52
- Last modified 11.04.2025 00:51:21
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows l...
CVE-2010-0768
- EPSS 0.23%
- Published 01.04.2010 19:30:00
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the U...
CVE-2010-0769
- EPSS 0.05%
- Published 01.04.2010 19:30:00
- Last modified 11.04.2025 00:51:21
IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by readin...