CVE-2003-1447
published 2003-12-31CVE-2003-1447: IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the…
PriorityP46low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.23%
14.2th percentile
IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2753-chm6-qr3j: IBM WebSphere Advanced Server Edition 4
ghsa_unreviewed·2022-04-29
CVE-2003-1447 [LOW] GHSA-2753-chm6-qr3j: IBM WebSphere Advanced Server Edition 4
IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
Red Hat
bind: implement source UDP port randomization (CERT VU#800113)
vendor_redhat·2008-07-08·CVSS 6.8
CVE-2008-1447 [MEDIUM] bind: implement source UDP port randomization (CERT VU#800113)
bind: implement source UDP port randomization (CERT VU#800113)
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://securityreason.com/securityalert/3277http://www.securityfocus.com/archive/1/310118http://www.securityfocus.com/archive/1/310796http://www.securityfocus.com/bid/6758https://exchange.xforce.ibmcloud.com/vulnerabilities/11245http://securityreason.com/securityalert/3277http://www.securityfocus.com/archive/1/310118http://www.securityfocus.com/archive/1/310796http://www.securityfocus.com/bid/6758https://exchange.xforce.ibmcloud.com/vulnerabilities/11245
2003-12-31
Published