Ibm

Websphere Application Server

519 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.4%
  • Veröffentlicht 14.11.2012 12:30:59
  • Zuletzt bearbeitet 16.06.2026 23:43:01

The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterprise, allows remote attackers to cause a denial of service (daemon outage) via a crafted request.

  • EPSS 2.41%
  • Veröffentlicht 14.11.2012 12:30:59
  • Zuletzt bearbeitet 16.06.2026 23:45:47

IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote attackers to gain privileges via unspecified vectors.

  • EPSS 1.83%
  • Veröffentlicht 14.11.2012 12:30:59
  • Zuletzt bearbeitet 16.06.2026 23:45:47

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.

  • EPSS 1.01%
  • Veröffentlicht 14.11.2012 12:30:59
  • Zuletzt bearbeitet 16.06.2026 23:45:47

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack the authentication of arbitrary users for reque...

  • EPSS 2.07%
  • Veröffentlicht 25.09.2012 20:55:01
  • Zuletzt bearbeitet 16.06.2026 23:42:57

The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.

  • EPSS 2.9%
  • Veröffentlicht 25.09.2012 20:55:01
  • Zuletzt bearbeitet 16.06.2026 23:42:57

Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.

  • EPSS 1.61%
  • Veröffentlicht 25.09.2012 20:55:01
  • Zuletzt bearbeitet 16.06.2026 23:42:57

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified im...

  • EPSS 0.36%
  • Veröffentlicht 25.09.2012 20:55:01
  • Zuletzt bearbeitet 16.06.2026 23:42:58

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does no...

  • EPSS 1.82%
  • Veröffentlicht 30.08.2012 22:55:04
  • Zuletzt bearbeitet 16.06.2026 23:43:01

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote authentic...

  • EPSS 2.37%
  • Veröffentlicht 21.08.2012 10:46:10
  • Zuletzt bearbeitet 16.06.2026 23:41:09

IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of servi...