Skip to main content

Vendor/product archive

ibm / websphere_application_server CVEs

Beta · best-effort

468 CVEs tagged to ibm / websphere_application_server50 Critical, 89 High, 288 Medium, 41 Low, 0 Unrated.

CVE-2011-1319

Published Mar 8, 2011

The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote authenticated users to cause a denial of service (me…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1318

Published Mar 8, 2011

Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote att…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1317

Published Mar 8, 2011

Memory leak in com.ibm.ws.jsp.runtime.WASJSPStrBufferImpl in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1316

Published Mar 8, 2011

The Session Initiation Protocol (SIP) Proxy in the HTTP Transport component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1315

Published Mar 8, 2011

Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via network…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1314

Published Mar 8, 2011

The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (daemon hang) by…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1313

Published Mar 8, 2011

Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote backend IIOP servers to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1312

Published Mar 8, 2011

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1311

Published Mar 8, 2011

The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1310

Published Mar 8, 2011

The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin com…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1309

Published Mar 8, 2011

The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1308

Published Mar 8, 2011

Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) before 7.0.0.15…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1307

Published Mar 8, 2011

The installer in IBM WebSphere Application Server (WAS) before 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to l…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-7274

Published Feb 15, 2011

IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not provid…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0316

Published Jan 12, 2011

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict access to console servlets, w…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0315

Published Jan 12, 2011

Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4220

Published Nov 9, 2010

Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Console component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0786

Published Nov 9, 2010

The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0785

Published Nov 9, 2010

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote a…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0784

Published Nov 9, 2010

Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary we…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0783

Published Nov 9, 2010

Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attacker…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0781

Published Sep 21, 2010

Unspecified vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 allows remote authenticated users to cause a denial of servic…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3186

Published Aug 30, 2010

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is u…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 301-325 of 468 CVEsPage 13 of 19