CVE-2003-1447
- EPSS 0.23%
- Veröffentlicht 31.12.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:04:27
IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
- EPSS 3.36%
- Veröffentlicht 11.10.2002 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:58:49
IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".
CVE-2001-1189
- EPSS 0.33%
- Veröffentlicht 13.12.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:55:46
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
CVE-2001-0824
- EPSS 2.27%
- Veröffentlicht 06.12.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:55:01
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the J...
CVE-2001-0962
- EPSS 1.59%
- Veröffentlicht 19.09.2001 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:55:18
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
- EPSS 1.45%
- Veröffentlicht 02.07.2001 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:54:12
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
- EPSS 5.09%
- Veröffentlicht 02.07.2001 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:54:13
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
- EPSS 3.32%
- Veröffentlicht 13.03.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:53:41
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad requ...
- EPSS 6.41%
- Veröffentlicht 14.11.2000 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:52:35
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
- EPSS 7.83%
- Veröffentlicht 24.07.2000 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:52:11
IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.