- EPSS 0.64%
- Veröffentlicht 27.06.2006 10:05:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."
- EPSS 0.94%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".
- EPSS 2.07%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
CVE-2006-2431
- EPSS 1.44%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitr...
CVE-2006-2432
- EPSS 1.49%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
- EPSS 0.94%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".
- EPSS 0.55%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.
CVE-2006-2435
- EPSS 0.93%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
CVE-2006-2436
- EPSS 0.75%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.
CVE-2006-2342
- EPSS 1.25%
- Veröffentlicht 12.05.2006 17:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.