Skip to main content

Vendor/product archive

ibm / websphere_application_server CVEs

Beta · best-effort

468 CVEs tagged to ibm / websphere_application_server50 Critical, 89 High, 288 Medium, 41 Low, 0 Unrated.

CVE-2012-2190

Published Aug 21, 2012

IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2170

Published Jun 20, 2012

The Application Snoop Servlet in IBM WebSphere Application Server 7.0 before 7.0.0.23 does not properly restrict access, which allows remote attackers to obtain sensitive client a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0720

Published Jun 20, 2012

Cross-site scripting (XSS) vulnerability in the Integration Solution Console in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote at…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0717

Published Jun 20, 2012

IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client authentication is used, allows remote attackers to bypass X.509 client-certifi…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-0716

Published Jun 20, 2012

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web scri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2162

Published May 1, 2012

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0707

Published Feb 23, 2012

Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach tha…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0193

Published Jan 20, 2012

IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without rest…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1376

Published Jan 19, 2012

iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/i…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5066

Published Jan 15, 2012

The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integrat…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-5065

Published Jan 15, 2012

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1377

Published Jan 15, 2012

The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Sec…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1362

Published Jan 15, 2012

Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2748

Published Oct 30, 2011

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2747

Published Oct 30, 2011

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1368

Published Oct 29, 2011

The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to rea…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1359

Published Sep 6, 2011

Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1356

Published Jul 19, 2011

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Cons…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1355

Published Jul 19, 2011

Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3271

Published Jul 18, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1209

Published May 4, 2011

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Security XML encryption algorithm, which makes it easier for remote attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1683

Published Apr 13, 2011

IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registry or Federated Repository with…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1322

Published Mar 8, 2011

The SOAP with Attachments API for Java (SAAJ) implementation in the Web Services component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.1…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1321

Published Mar 8, 2011

The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 does not purge a user from t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1320

Published Mar 8, 2011

The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when the Tivoli Integrated Portal / embedded WebSphere Applicatio…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 468 CVEsPage 12 of 19