CVE-2010-0770
published 2010-04-01CVE-2010-0770: IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of…
PriorityP414medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.75%
75.5th percentile
IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | <= 6.0.2.39 | — |
| ibm | websphere_application_server | <= 6.1.0.29 | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
GPL FTP SITE overflow attempt
suricata·2010-09-23
CVE-1999-0838 GPL FTP SITE overflow attempt
GPL FTP SITE overflow attempt
Rule: alert ftp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL FTP SITE overflow attempt"; flow:established,to_server; content:"SITE"; nocase; isdataat:100,relative; pcre:"/^SITE\s[^\n]{100}/smi"; reference:cve,1999-0838; reference:cve,2001-0755; reference:cve,2001-0770; classtype:attempted-admin; sid:2101529; rev:13; metadata:created_at 2010_09_23, cve CVE_1999_0838, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
No public exploits indexed.
Bugzilla
CVE-2010-4174 RHDS/389: information disclosure in audit logs
bugzilla·2010-11-16·CVSS 3.3
CVE-2010-4174 [LOW] CVE-2010-4174 RHDS/389: information disclosure in audit logs
CVE-2010-4174 RHDS/389: information disclosure in audit logs
When audit logging is enabled on Red Hat Directory Server and 389 Directory Server, changes to cn=config:nsslapd-rootpw result in the password value being logged in cleartext. The audit log records an entry similar to the following:
dn: cn=config
changetype: modify
replace: nsslapd-rootpw
nsslapd-rootpw: secret
User passwords, however, are not logged verbatim but in hashed form.
Although the directory server administrator can configure the path and permissions of the audit log, by default it is mode 0600, owned by the directory server user, and is located in the directory server log directory (/var/log/dirsrv/slapd-[hostname]), which is mode 0770 and owned by the directory server user ("nobody", by default)
Discussion:
Crea
Bugzilla
CVE-2010-3560 JDK unspecified vulnerability in Networking component
bugzilla·2010-10-13·CVSS 2.6
CVE-2010-3560 [LOW] CVE-2010-3560 JDK unspecified vulnerability in Networking component
CVE-2010-3560 JDK unspecified vulnerability in Networking component
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the Networking component (CVE-2010-3560). The CVSSv2 scored upstream is
cvss2=2.6/AV:N/AC:H/Au:N/C:P/I:N/A:N
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Extras for Red Hat Enterprise Linux 6
Via RHSA-2010:0987 https://rhn.redhat.com/errata/RHSA-2010-0987.html
---
This issue has been addressed in following
Bugzilla
CVE-2010-3572 JDK unspecified vulnerability in Sound component
bugzilla·2010-10-13·CVSS 10.0
CVE-2010-3572 [CRITICAL] CVE-2010-3572 JDK unspecified vulnerability in Sound component
CVE-2010-3572 JDK unspecified vulnerability in Sound component
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the Sound component (CVE-2010-3572). The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 3
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0786 https://rhn.redhat.com/errata/RHSA-2010-0786.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Bugzilla
CVE-2010-3563 OpenJDK: unspecified vulnerability in Deployment component
bugzilla·2010-10-13·CVSS 10.0
CVE-2010-3563 [CRITICAL] CVE-2010-3563 OpenJDK: unspecified vulnerability in Deployment component
CVE-2010-3563 OpenJDK: unspecified vulnerability in Deployment component
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2010-3563). The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Extras for Red Hat Enterprise Linux 6
Via RHSA-2010:0987 https://rhn.redhat.com/errata/RHSA-2010-0987.html
---
This issue has been addressed in foll
Bugzilla
CVE-2010-3556 JDK unspecified vulnerability in 2D component
bugzilla·2010-10-13·CVSS 10.0
CVE-2010-3556 [CRITICAL] CVE-2010-3556 JDK unspecified vulnerability in 2D component
CVE-2010-3556 JDK unspecified vulnerability in 2D component
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the 2D component (CVE-2010-3556). The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 3
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0786 https://rhn.redhat.com/errata/RHSA-2010-0786.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras
Bugzilla
CVE-2010-3570 JDK unspecified vulnerability in Deployment Toolkit
bugzilla·2010-10-13·CVSS 7.6
CVE-2010-3570 [HIGH] CVE-2010-3570 JDK unspecified vulnerability in Deployment Toolkit
CVE-2010-3570 JDK unspecified vulnerability in Deployment Toolkit
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment Toolkit (CVE-2010-3570). The CVSSv2 scored upstream is
cvss2=5.1/AV:N/AC:H/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
Bugzilla
CVE-2010-3558 JDK unspecified vulnerability in Java Web Start component
bugzilla·2010-10-13·CVSS 10.0
CVE-2010-3558 [CRITICAL] CVE-2010-3558 JDK unspecified vulnerability in Java Web Start component
CVE-2010-3558 JDK unspecified vulnerability in Java Web Start component
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the Java Web Start component (CVE-2010-3558). The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Extras for Red Hat Enterprise Linux 6
Via RHSA-2010:0987 https://rhn.redhat.com/errata/RHSA-2010-0987.html
---
This issue has been addressed in f
Bugzilla
CVE-2010-3559 JDK unspecified vulnerability in Sound component
bugzilla·2010-10-13·CVSS 10.0
CVE-2010-3559 [CRITICAL] CVE-2010-3559 JDK unspecified vulnerability in Sound component
CVE-2010-3559 JDK unspecified vulnerability in Sound component
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the Sound component (CVE-2010-3559). The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0807 https://rhn.redhat.com/errata/RHSA-2010-0807.html
---
This issue has been addressed in following products:
Extras for Red Hat Enterprise Linux
Bugzilla
CVE-2010-3550 JDK unspecified vulnerability in Java Web Start component
bugzilla·2010-10-13·CVSS 9.3
CVE-2010-3550 [CRITICAL] CVE-2010-3550 JDK unspecified vulnerability in Java Web Start component
CVE-2010-3550 JDK unspecified vulnerability in Java Web Start component
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the Java Web Start component (CVE-2010-3550). The CVSSv2 scored upstream is
cvss2=6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0807 https://rhn.redhat.com/errata/RHSA-2010-0807.html
---
This issue has been addressed in following products:
Extras for Red Hat
Bugzilla
CVE-2010-3571 JDK unspecified vulnerability in 2D component
bugzilla·2010-10-13·CVSS 10.0
CVE-2010-3571 [CRITICAL] CVE-2010-3571 JDK unspecified vulnerability in 2D component
CVE-2010-3571 JDK unspecified vulnerability in 2D component
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the 2D component (CVE-2010-3571). The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.htm
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 3
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0786 https://rhn.redhat.com/errata/RHSA-2010-0786.html
---
This issue has been addressed in following products:
RHEL 4 for SAP
RHEL 5 for
Bugzilla
CVE-2010-3552 JDK unspecified vulnerability in New Java Plugin component
bugzilla·2010-10-13·CVSS 10.0
CVE-2010-3552 [CRITICAL] CVE-2010-3552 JDK unspecified vulnerability in New Java Plugin component
CVE-2010-3552 JDK unspecified vulnerability in New Java Plugin component
Update 22 of Oracle/Sun Java fixes an unspecified vulnerability in the New Java Plugin component (CVE-2010-3552). The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
Bugzilla
CVE-2010-3553 OpenJDK Swing unsafe reflection usage (6622002)
bugzilla·2010-10-12·CVSS 10.0
CVE-2010-3553 [CRITICAL] CVE-2010-3553 OpenJDK Swing unsafe reflection usage (6622002)
CVE-2010-3553 OpenJDK Swing unsafe reflection usage (6622002)
The UIDefault.ProxyLazyValue class has unsafe reflection usage.
It did not properly check the permissions of the caller and allowed untrusted
callers to create objects via ProxyLazyValue
UIDefault.ProxyLazyValue.(CVE-2010-3553)
The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0768 https://rhn.redhat.com/errata/RHSA-2010-0768.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
Bugzilla
CVE-2010-3566 OpenJDK ICC Profile remote code execution (6963489)
bugzilla·2010-10-04·CVSS 10.0
CVE-2010-3566 [CRITICAL] CVE-2010-3566 OpenJDK ICC Profile remote code execution (6963489)
CVE-2010-3566 OpenJDK ICC Profile remote code execution (6963489)
ICC Profile Device Information Tag Remote Code Execution Vulnerability.
This issue (CVE-2010-3566) is not exploitable when using OpenJDK on Red Hat Enterprise Linux 5 and 6; however, the fix was added as a defense in depth patch.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0768 https://rhn.redhat.com/errata/RHSA-2010-0768.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0807 https://rhn.red
Bugzilla
CVE-2010-3568 OpenJDK Deserialization Race condition (6559775)
bugzilla·2010-10-04·CVSS 10.0
CVE-2010-3568 [CRITICAL] CVE-2010-3568 OpenJDK Deserialization Race condition (6559775)
CVE-2010-3568 OpenJDK Deserialization Race condition (6559775)
Race condition in the way objects were deserialized could allow an untrusted applet or application to misuse the privileges of the user running the applet or application. (CVE-2010-3568)
The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0768 https://rhn.redhat.com/errata/RHSA-2010-0768.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in fo
Bugzilla
CVE-2010-3557 OpenJDK Swing mutable static (6938813)
bugzilla·2010-10-04·CVSS 6.8
CVE-2010-3557 [MEDIUM] CVE-2010-3557 OpenJDK Swing mutable static (6938813)
CVE-2010-3557 OpenJDK Swing mutable static (6938813)
Flaws in the Swing library could allow an untrusted application to modify the
behavior and state of certain JDK classes. (CVE-2010-3557)
The CVSSv2 scored upstream is
cvss2=6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0768 https://rhn.redhat.com/errata/RHSA-2010-0768.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 3
Extras for RHEL 4
Extra
http://secunia.com/advisories/39140http://www-01.ibm.com/support/docview.wss?uid=swg1PK93653http://www.securityfocus.com/bid/39056https://exchange.xforce.ibmcloud.com/vulnerabilities/57182http://secunia.com/advisories/39140http://www-01.ibm.com/support/docview.wss?uid=swg1PK93653http://www.securityfocus.com/bid/39056https://exchange.xforce.ibmcloud.com/vulnerabilities/57182
2010-04-01
Published