- EPSS 1.04%
- Veröffentlicht 20.01.2012 04:04:51
- Zuletzt bearbeitet 29.04.2026 01:13:23
IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allow...
CVE-2011-1376
- EPSS 0.04%
- Veröffentlicht 19.01.2012 11:55:10
- Zuletzt bearbeitet 29.04.2026 01:13:23
iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/isclite.ear/ and bin/client_ffdc/, which allows local users to read or m...
CVE-2011-5066
- EPSS 0.05%
- Veröffentlicht 15.01.2012 03:55:13
- Zuletzt bearbeitet 29.04.2026 01:13:23
The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (...
CVE-2011-1362
- EPSS 0.23%
- Veröffentlicht 15.01.2012 03:55:12
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrar...
- EPSS 1.37%
- Veröffentlicht 15.01.2012 03:55:12
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack...
CVE-2011-5065
- EPSS 0.43%
- Veröffentlicht 15.01.2012 03:55:12
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.
- EPSS 0.21%
- Veröffentlicht 30.10.2011 10:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows re...
CVE-2009-2748
- EPSS 0.23%
- Veröffentlicht 30.10.2011 10:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- EPSS 0.21%
- Veröffentlicht 29.10.2011 10:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to read unspecified files via unknown vectors.
- EPSS 0.19%
- Veröffentlicht 06.09.2011 15:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.