- EPSS 0.51%
- Published 01.04.2010 19:30:00
- Last modified 11.04.2025 00:51:21
IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.
CVE-2010-1182
- EPSS 0.4%
- Published 29.03.2010 20:30:00
- Last modified 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.
- EPSS 86.82%
- Published 05.03.2010 19:30:00
- Last modified 24.07.2025 17:43:53
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an...
- EPSS 0.45%
- Published 08.02.2010 21:30:00
- Last modified 11.04.2025 00:51:21
The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network ...
CVE-2009-2749
- EPSS 0.44%
- Published 08.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.
CVE-2009-2746
- EPSS 0.16%
- Published 16.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 allows remote attackers to hijack the...
CVE-2009-2742
- EPSS 0.23%
- Published 21.09.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.
CVE-2009-2743
- EPSS 0.06%
- Published 21.09.2009 19:30:00
- Last modified 09.04.2025 00:30:58
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sen...
CVE-2009-2744
- EPSS 0.84%
- Published 21.09.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25."
- EPSS 0.11%
- Published 08.09.2009 22:30:00
- Last modified 09.04.2025 00:30:58
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, which allows remote attackers to bypass intended acc...