cbcvebase.

Ibm Websphere Application Server vulnerabilities

477 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
477
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL63HIGH109MEDIUM265LOW40

Vulnerabilities

Page 24 of 24
CVE-2013-0541P4LOWCVSS 1.9v6.1.0.0v6.1.0.1+51 more2013-04-24
CVE-2013-0541 [LOW] CWE-119 CVE-2013-0541: Buffer overflow in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, Buffer overflow in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Windows, when a localOS registry is used in conjunction with WebSphere Identity Manger (WIM), allows local users to cause a denial of service (daemon crash) via unspecified vectors.
nvd
CVE-2009-2743P4LOWCVSS 2.1v6.1v6.1.0.1+20 more2009-09-21
CVE-2009-2743 [LOW] CVE-2009-2743: IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properl IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.
nvd
CVE-2009-1173P4LOWCVSS 2.1v7.0v7.0.0.12009-03-31
CVE-2009-1173 [LOW] CWE-264 CVE-2009-1173: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files asso IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.
nvd
CVE-2009-2087P4LOWCVSS 2.1v6.1v6.1.0+29 more2009-08-13
CVE-2009-2087 [LOW] CWE-255 CVE-2009-2087: The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfuscation, which allows local users to cause a denial of service (deployment failure) via unspecified vectors.
nvd
CVE-2010-1650P4LOWCVSS 1.9v6.0v6.0.0.1+92 more2010-05-03
CVE-2010-1650 [LOW] CWE-310 CVE-2010-1650: IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x befor IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified objects, which allows attackers to obtain sensitive information by reading the trace output.
nvd
CVE-2003-1447P4LOWCVSS 1.9v4.0.42003-12-31
CVE-2003-1447 [LOW] CWE-310 CVE-2003-1447: IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encodin IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
nvd
CVE-2011-1356P4LOWCVSS 2.1v6.1v6.1.0+42 more2011-07-19
CVE-2011-1356 [LOW] CWE-200 CVE-2011-1356: IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local user IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Console request.
nvd
CVE-2011-5066P4LOWCVSS 2.1v6.1v6.1.0+29 more2012-01-15
CVE-2011-5066 [LOW] CWE-200 CVE-2011-5066: The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Applicati The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (FFDC) introspection code, which allows local users to obtain sensitive information by reading the FFDC log
nvd
CVE-2013-2976P4LOWCVSS 1.9v8.0.0.0v8.0.0.1+70 more2013-08-21
CVE-2013-2976 [LOW] CWE-200 CVE-2013-2976: The Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before The Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 does not properly perform caching, which allows local users to obtain sensitive information via unspecified vectors.
nvd
CVE-2010-1651P4LOWCVSS 1.9v6.1v6.1.0+42 more2010-05-03
CVE-2010-1651 [LOW] CWE-310 CVE-2010-1651: IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic a IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log.
nvd
CVE-2011-1310P4LOWCVSS 1.9v6.1.0v6.1.0.0+30 more2011-03-08
CVE-2011-1310 [LOW] CWE-200 CVE-2011-1310: The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x befor The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which allows local users to obtain potentially sensitive information by reading these files.
nvd
CVE-2009-0504P4LOWCVSS 2.1≤ 7.02009-02-17
CVE-2009-0504 [LOW] CWE-200 CVE-2009-0504: WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0. WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.
nvd
CVE-2011-1307P4LOWCVSS 2.1≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1307 [LOW] CVE-2011-1307: The installer in IBM WebSphere Application Server (WAS) before 7.0.0.15 uses 777 permissions for a t The installer in IBM WebSphere Application Server (WAS) before 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to log files via standard filesystem operations, a different vulnerability than CVE-2009-1173.
nvd
CVE-2010-0769P4LOWCVSS 1.9≤ 6.0.2.39v6.0+46 more2010-04-01
CVE-2010-0769 [LOW] CWE-255 CVE-2010-0769: IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0. IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by reading a cleartext field in the resources.xml file.
nvd
CVE-2008-0740P4LOWCVSS 2.1≤ 6.0.2.242008-02-13
CVE-2008-0740 [LOW] CWE-264 CVE-2008-0740: IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 1 IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.
nvd
CVE-2009-0434P4LOWCVSS 1.9v6.0v6.0.0.1+54 more2009-02-10
CVE-2009-0434 [LOW] CVE-2009-0434: PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x b PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate
nvd
CVE-2009-0437P4LOWCVSS 1.9v6.0.22009-02-10
CVE-2009-0437 [LOW] CWE-200 CVE-2009-0437: The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Wi The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase