Vulnerabilities > IBM > Low

DATE CVE VULNERABILITY TITLE RISK
2009-03-31 CVE-2009-1173 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere Application Server 7.0/7.0.0.1
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.
local
low complexity
ibm CWE-264
2.1
2009-03-04 CVE-2009-0809 Permissions, Privileges, and Access Controls vulnerability in multiple products
The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.
network
3ds ibm CWE-264
3.5
2009-02-17 CVE-2009-0504 Information Exposure vulnerability in IBM Websphere Application Server
WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.
local
low complexity
ibm CWE-200
2.1
2009-02-13 CVE-2009-0503 Credentials Management vulnerability in IBM Websphere Message Broker 6.1/6.1.0.1
IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.
local
low complexity
ibm CWE-255
2.1
2009-02-10 CVE-2009-0433 Multiple vulnerability in IBM WebSphere Application Server
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash) via unknown vectors, related to a mishandling of client read failures in which clients receive many 500 HTTP error responses and backend servers are incorrectly labeled as down.
network
high complexity
ibm
2.6
2009-02-10 CVE-2009-0434 Information Exposure vulnerability in IBM Websphere Application Server
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files.
local
ibm CWE-200
1.9
2009-02-10 CVE-2009-0437 Information Exposure vulnerability in IBM Websphere Application Server 6.0.2
The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.
1.9
2008-11-25 CVE-2008-5228 Cross-Site Scripting vulnerability in IBM Workplace Content Management 6.0/6.1
Cross-site scripting (XSS) vulnerability in IBM Workplace Content Management (WCM) 6.0G and 6.1 before CF8, when a Page Navigation Component shows menu entries, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in the URI, related to parameters "not being encoded."
network
high complexity
ibm CWE-79
2.6
2008-11-12 CVE-2008-5043 Cross-Site Scripting vulnerability in IBM Metrica Service Assurance Framework
Multiple cross-site scripting (XSS) vulnerabilities in the web-based interface in IBM Metrica Service Assurance Framework allow remote authenticated users to inject arbitrary web script or HTML via (1) the elementid parameter in a generatedreportresults action to the ReportTree program, (2) the jnlpname parameter to the Launch program, or (3) the :tasklabel parameter to the ReportRequest program, related to the name of a report.
network
ibm CWE-79
3.5
2008-10-31 CVE-2008-4807 Credentials Management vulnerability in IBM Lotus Connections
IBM Lotus Connections 2.x before 2.0.1 stores the password for the administrative user in the trace.log file, which allows local users to obtain sensitive information by reading this file.
local
low complexity
ibm CWE-255
2.1