- EPSS 0.37%
- Veröffentlicht 10.02.2009 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.17 on AIX 5.3 allows attackers to cause a denial of service ...
CVE-2009-0436
- EPSS 0.06%
- Veröffentlicht 10.02.2009 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack v...
CVE-2009-0437
- EPSS 0.06%
- Veröffentlicht 10.02.2009 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log fi...
- EPSS 0.21%
- Veröffentlicht 10.02.2009 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412.
CVE-2009-0391
- EPSS 0.44%
- Veröffentlicht 02.02.2009 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.
- EPSS 0.43%
- Veröffentlicht 10.12.2008 00:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
- EPSS 1.35%
- Veröffentlicht 10.12.2008 00:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs. NOTE: this is probably a duplicate of CVE-2009-0438.
- EPSS 0.3%
- Veröffentlicht 10.12.2008 00:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of...
- EPSS 1.27%
- Veröffentlicht 10.12.2008 00:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 has unknown impact and attack vectors related to "userNameToken."
CVE-2008-4678
- EPSS 1.97%
- Veröffentlicht 22.10.2008 18:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host heade...