Ibm

Websphere Application Server

492 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.17%
  • Veröffentlicht 08.02.2010 21:30:00
  • Zuletzt bearbeitet 16.06.2026 23:16:24

The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network ...

  • EPSS 1.15%
  • Veröffentlicht 08.12.2009 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:10:09

Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.

  • EPSS 0.6%
  • Veröffentlicht 16.11.2009 19:30:00
  • Zuletzt bearbeitet 16.06.2026 23:10:09

Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 allows remote attackers to hijack the...

  • EPSS 1.64%
  • Veröffentlicht 21.09.2009 19:30:00
  • Zuletzt bearbeitet 16.06.2026 23:10:08

Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.

  • EPSS 0.39%
  • Veröffentlicht 21.09.2009 19:30:00
  • Zuletzt bearbeitet 16.06.2026 23:10:08

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sen...

  • EPSS 2.52%
  • Veröffentlicht 21.09.2009 19:30:00
  • Zuletzt bearbeitet 16.06.2026 23:10:08

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25."

  • EPSS 2.78%
  • Veröffentlicht 08.09.2009 22:30:00
  • Zuletzt bearbeitet 16.06.2026 23:10:57

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, which allows remote attackers to bypass intended acc...

  • EPSS 1.21%
  • Veröffentlicht 13.08.2009 18:30:00
  • Zuletzt bearbeitet 16.06.2026 23:06:04

The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access vi...

  • EPSS 2.37%
  • Veröffentlicht 13.08.2009 18:30:00
  • Zuletzt bearbeitet 16.06.2026 23:08:43

The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrict...

  • EPSS 0.22%
  • Veröffentlicht 13.08.2009 18:30:00
  • Zuletzt bearbeitet 16.06.2026 23:08:44

The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfusca...