Ibm

Websphere Application Server

519 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.19%
  • Veröffentlicht 08.03.2011 21:59:34
  • Zuletzt bearbeitet 16.06.2026 23:29:07

The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.

  • EPSS 0.27%
  • Veröffentlicht 08.03.2011 21:59:34
  • Zuletzt bearbeitet 16.06.2026 23:29:07

The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, ...

  • EPSS 0.86%
  • Veröffentlicht 08.03.2011 21:59:34
  • Zuletzt bearbeitet 16.06.2026 23:29:07

The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.x...

  • EPSS 1.03%
  • Veröffentlicht 08.03.2011 21:59:34
  • Zuletzt bearbeitet 16.06.2026 23:29:07

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended...

  • EPSS 0.93%
  • Veröffentlicht 08.03.2011 21:59:34
  • Zuletzt bearbeitet 16.06.2026 23:29:08

Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote backend IIOP servers to cause a denial of service (S0C4 ABEND and storage corruption) by rejecting IIOP requests at oppo...

  • EPSS 1.11%
  • Veröffentlicht 08.03.2011 21:59:34
  • Zuletzt bearbeitet 16.06.2026 23:29:08

The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (daemon hang) by performing close operations via network connections to a queue manager.

  • EPSS 1.11%
  • Veröffentlicht 08.03.2011 21:59:34
  • Zuletzt bearbeitet 16.06.2026 23:29:08

Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via network connections associated with a NULL return value from a synchronous JMS...

  • EPSS 1.11%
  • Veröffentlicht 08.03.2011 21:59:34
  • Zuletzt bearbeitet 16.06.2026 23:29:08

The Session Initiation Protocol (SIP) Proxy in the HTTP Transport component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (worker thread exhaustion and UDP messaging outage) by sending ...

  • EPSS 0.97%
  • Veröffentlicht 15.02.2011 01:00:01
  • Zuletzt bearbeitet 16.06.2026 23:03:58

IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password.

  • EPSS 1.92%
  • Veröffentlicht 12.01.2011 01:00:02
  • Zuletzt bearbeitet 16.06.2026 23:27:10

Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors ...