- EPSS 0.3%
- Veröffentlicht 18.06.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_create.log file that is associated with profile creation by the BBOWWPFx job and the zPMT.
CVE-2010-2324
- EPSS 0.4%
- Veröffentlicht 18.06.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows attackers to perform unspecified "link injection" actions via unknown vectors.
CVE-2010-2325
- EPSS 0.25%
- Veröffentlicht 18.06.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "U...
CVE-2010-2326
- EPSS 0.49%
- Veröffentlicht 18.06.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11, when addNode -trace is used during node federation, allows attackers to obtain sensitive information about CIMMetadataCollectorImpl trace actions by reading the addNode.log file.
CVE-2010-2327
- EPSS 0.76%
- Veröffentlicht 18.06.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod_ibm_ssl in IBM HTTP Server 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11, as used in IBM WebSphere Application Server (WAS) on z/OS, does not properly handle a large HTTP request body in uploading over SSL, which might allow r...
- EPSS 0.53%
- Veröffentlicht 18.06.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (NullPointerException) via a large amount of chunked data that uses gzip compression.
CVE-2010-0774
- EPSS 0.14%
- Veröffentlicht 17.05.2010 22:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 do not properly handle WebServices PKCS#7 and PKIPath tokens, which all...
- EPSS 0.53%
- Veröffentlicht 17.05.2010 22:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a crafted request, re...
- EPSS 0.53%
- Veröffentlicht 17.05.2010 22:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle chunked transfer encoding during a call to response.sendRedirect, which allows remote attackers to ...
CVE-2010-0777
- EPSS 0.55%
- Veröffentlicht 17.05.2010 22:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote atta...