CVE-2008-5413
published 2008-12-10CVE-2008-5413: PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information…
PriorityP418medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.45%
70.6th percentile
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2009-0434.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | <= 7.0 | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cwj6-r3ph-3rpm: PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7
ghsa_unreviewed·2022-05-17·CVSS 1.9
CVE-2008-5413 [LOW] CWE-200 GHSA-cwj6-r3ph-3rpm: PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2009-0434.
GHSA
GHSA-mc69-478q-9cxf: PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-0434 [MEDIUM] CWE-200 GHSA-mc69-478q-9cxf: PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2008-5413.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg27014463http://www-1.ibm.com/support/docview.wss?uid=swg1PK63886http://www.securityfocus.com/bid/32679http://www.vupen.com/english/advisories/2008/3370http://www.vupen.com/english/advisories/2009/0423http://www-01.ibm.com/support/docview.wss?uid=swg27014463http://www-1.ibm.com/support/docview.wss?uid=swg1PK63886http://www.securityfocus.com/bid/32679http://www.vupen.com/english/advisories/2008/3370http://www.vupen.com/english/advisories/2009/0423
2008-12-10
Published