- EPSS 1.94%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.06.2026 22:24:59
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".
- EPSS 2.84%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.06.2026 22:24:59
IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
CVE-2006-2431
- EPSS 3.01%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.06.2026 22:24:59
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitr...
CVE-2006-2432
- EPSS 2.54%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.06.2026 22:24:59
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
- EPSS 1.88%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.06.2026 22:25:00
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".
- EPSS 1.74%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.06.2026 22:25:00
Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.
CVE-2006-2435
- EPSS 2.57%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.06.2026 22:25:00
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
CVE-2006-2436
- EPSS 1.98%
- Veröffentlicht 17.05.2006 10:06:00
- Zuletzt bearbeitet 16.06.2026 22:25:00
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.
CVE-2006-2342
- EPSS 2.74%
- Veröffentlicht 12.05.2006 17:06:00
- Zuletzt bearbeitet 16.06.2026 22:24:49
IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.
- EPSS 1.6%
- Veröffentlicht 05.04.2006 10:04:00
- Zuletzt bearbeitet 16.06.2026 22:23:18
IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header.