Ibm

Websphere Application Server

439 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.76%
  • Veröffentlicht 11.04.2007 01:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.

  • EPSS 1.14%
  • Veröffentlicht 22.03.2007 23:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid mu...

  • EPSS 0.23%
  • Veröffentlicht 20.03.2007 10:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive informa...

  • EPSS 0.4%
  • Veröffentlicht 20.03.2007 10:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 allows remote attackers to obtain JSP source code and other sensitive information via certain "special URIs."

  • EPSS 0.4%
  • Veröffentlicht 20.03.2007 10:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a specific JSP URL."

  • EPSS 2.07%
  • Veröffentlicht 19.12.2006 20:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.

  • EPSS 1.21%
  • Veröffentlicht 19.12.2006 20:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive...

  • EPSS 0.99%
  • Veröffentlicht 28.11.2006 02:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Potential security exposure" (PK...

  • EPSS 1.21%
  • Veröffentlicht 28.11.2006 02:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering of response operation," which has unknown impact and attack vectors.

  • EPSS 0.66%
  • Veröffentlicht 17.10.2006 17:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.