Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2009-08-13 CVE-2009-2087 Credentials Management vulnerability in IBM Websphere Application Server
The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfuscation, which allows local users to cause a denial of service (deployment failure) via unspecified vectors.
local
low complexity
ibm CWE-255
2.1
2009-08-13 CVE-2009-2089 Configuration vulnerability in IBM Websphere Application Server
The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by reading a Migration Trace file.
network
high complexity
ibm CWE-16
2.1
2009-08-13 CVE-2009-2094 Unspecified vulnerability in IBM Websphere Commerce
Unspecified vulnerability in IBM WebSphere Commerce 6.0 Enterprise before 6.0.0.8, when trace is enabled, allows local users to obtain sensitive information via unknown vectors.
local
ibm
1.5
2009-06-03 CVE-2009-1905 Improper Authentication vulnerability in IBM DB2
The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors.
network
high complexity
ibm CWE-287
2.6
2009-04-14 CVE-2009-1292 Information Exposure vulnerability in IBM Rational Clearcase
UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0.1.x before 7.0.1.4, and 7.1.x before 7.1.0.1 on Linux and AIX places a username and password on the command line, which allows local users to obtain credentials by listing the process.
local
low complexity
ibm unix CWE-200
2.1
2009-03-31 CVE-2003-1570 Improper Authentication vulnerability in IBM Tivoli Storage Manager
The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."
network
ibm CWE-287
3.5
2009-03-31 CVE-2009-1173 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere Application Server 7.0/7.0.0.1
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.
local
low complexity
ibm CWE-264
2.1
2009-03-04 CVE-2009-0809 Permissions, Privileges, and Access Controls vulnerability in multiple products
The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.
network
3ds ibm CWE-264
3.5
2009-02-17 CVE-2009-0504 Information Exposure vulnerability in IBM Websphere Application Server
WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.
local
low complexity
ibm CWE-200
2.1
2009-02-13 CVE-2009-0503 Credentials Management vulnerability in IBM Websphere Message Broker 6.1/6.1.0.1
IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.
local
low complexity
ibm CWE-255
2.1