Ibm

Websphere Application Server

443 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 13.08.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfusca...

  • EPSS 0.55%
  • Veröffentlicht 13.08.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass ...

  • EPSS 0.21%
  • Veröffentlicht 13.08.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by readin...

  • EPSS 0.36%
  • Veröffentlicht 13.08.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allows remote attackers to bypass intended Java Management Extensions (JMX) Management Beans (aka MBeans) ...

  • EPSS 0.22%
  • Veröffentlicht 13.08.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new applications, which allows remote attackers to obtain sensitive information via unspecified vectors.

  • EPSS 0.3%
  • Veröffentlicht 13.08.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors.

  • EPSS 2.22%
  • Veröffentlicht 14.07.2009 23:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLog...

  • EPSS 0.25%
  • Veröffentlicht 05.07.2009 16:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify ...

  • EPSS 0.4%
  • Veröffentlicht 25.06.2009 01:30:01
  • Zuletzt bearbeitet 23.04.2026 00:35:47

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPA...

  • EPSS 0.34%
  • Veröffentlicht 03.06.2009 17:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migratio...