Ibm

Websphere Application Server

443 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 10.02.2009 22:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.17 on AIX 5.3 allows attackers to cause a denial of service ...

  • EPSS 0.06%
  • Veröffentlicht 10.02.2009 22:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack v...

  • EPSS 0.06%
  • Veröffentlicht 10.02.2009 22:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log fi...

  • EPSS 0.21%
  • Veröffentlicht 10.02.2009 22:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412.

  • EPSS 0.44%
  • Veröffentlicht 02.02.2009 22:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.

  • EPSS 0.43%
  • Veröffentlicht 10.12.2008 00:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

  • EPSS 1.35%
  • Veröffentlicht 10.12.2008 00:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs. NOTE: this is probably a duplicate of CVE-2009-0438.

  • EPSS 0.3%
  • Veröffentlicht 10.12.2008 00:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of...

  • EPSS 1.27%
  • Veröffentlicht 10.12.2008 00:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 has unknown impact and attack vectors related to "userNameToken."

  • EPSS 1.97%
  • Veröffentlicht 22.10.2008 18:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host heade...