Ibm

Websphere Application Server

439 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 03.05.2010 13:51:52
  • Zuletzt bearbeitet 11.04.2025 00:51:21

IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified obj...

  • EPSS 0.05%
  • Veröffentlicht 03.05.2010 13:51:52
  • Zuletzt bearbeitet 11.04.2025 00:51:21

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows l...

  • EPSS 0.23%
  • Veröffentlicht 01.04.2010 19:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the U...

  • EPSS 0.05%
  • Veröffentlicht 01.04.2010 19:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by readin...

  • EPSS 0.51%
  • Veröffentlicht 01.04.2010 19:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.

  • EPSS 0.4%
  • Veröffentlicht 29.03.2010 20:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.

Exploit
  • EPSS 86.82%
  • Veröffentlicht 05.03.2010 19:30:00
  • Zuletzt bearbeitet 24.07.2025 17:43:53

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an...

  • EPSS 0.45%
  • Veröffentlicht 08.02.2010 21:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network ...

  • EPSS 0.44%
  • Veröffentlicht 08.12.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.

  • EPSS 0.16%
  • Veröffentlicht 16.11.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 allows remote attackers to hijack the...