Ibm

Websphere Application Server

443 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 17.05.2010 22:30:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 do not properly handle WebServices PKCS#7 and PKIPath tokens, which all...

  • EPSS 0.53%
  • Veröffentlicht 17.05.2010 22:30:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a crafted request, re...

  • EPSS 0.53%
  • Veröffentlicht 17.05.2010 22:30:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle chunked transfer encoding during a call to response.sendRedirect, which allows remote attackers to ...

  • EPSS 0.55%
  • Veröffentlicht 17.05.2010 22:30:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote atta...

  • EPSS 0.07%
  • Veröffentlicht 03.05.2010 13:51:52
  • Zuletzt bearbeitet 29.04.2026 01:13:23

IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified obj...

  • EPSS 0.05%
  • Veröffentlicht 03.05.2010 13:51:52
  • Zuletzt bearbeitet 29.04.2026 01:13:23

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows l...

  • EPSS 0.23%
  • Veröffentlicht 01.04.2010 19:30:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the U...

  • EPSS 0.05%
  • Veröffentlicht 01.04.2010 19:30:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by readin...

  • EPSS 0.51%
  • Veröffentlicht 01.04.2010 19:30:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.

  • EPSS 0.4%
  • Veröffentlicht 29.03.2010 20:30:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.