Ibm

Websphere Application Server

519 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.27%
  • Veröffentlicht 06.12.2001 05:00:00
  • Zuletzt bearbeitet 16.06.2026 21:55:01

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the J...

  • EPSS 1.59%
  • Veröffentlicht 19.09.2001 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:55:18

IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.

Exploit
  • EPSS 1.45%
  • Veröffentlicht 02.07.2001 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:54:12

IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.

Exploit
  • EPSS 5.09%
  • Veröffentlicht 02.07.2001 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:54:13

IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.

Exploit
  • EPSS 3.32%
  • Veröffentlicht 13.03.2001 05:00:00
  • Zuletzt bearbeitet 16.06.2026 21:53:41

Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad requ...

Exploit
  • EPSS 6.41%
  • Veröffentlicht 14.11.2000 05:00:00
  • Zuletzt bearbeitet 16.06.2026 21:52:35

Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.

Exploit
  • EPSS 7.83%
  • Veröffentlicht 24.07.2000 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:52:11

IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.

  • EPSS 3.07%
  • Veröffentlicht 08.06.2000 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:51:51

IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.

  • EPSS 0.35%
  • Veröffentlicht 02.12.1999 05:00:00
  • Zuletzt bearbeitet 16.06.2026 21:49:11

IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.