Vulnerabilities > IBM > Websphere Application Server > 6.0.2.33

DATE CVE VULNERABILITY TITLE RISK
2008-12-10 CVE-2008-5412 Multiple Unspecified vulnerability in IBM WebSphere Application Server
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs.
network
low complexity
microsoft ibm
critical
10.0
2008-12-10 CVE-2008-5411 Cryptographic Issues vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
ibm CWE-310
5.0
2008-06-04 CVE-2008-2550 Remote Security vulnerability in Websphere Application Server
Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and attack vectors related to an attribute in the SOAP security header.
network
low complexity
ibm
5.0
2007-11-03 CVE-2007-5799 Cross-Site Request Forgery (CSRF) vulnerability in IBM Websphere Application Server
Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
network
ibm CWE-352
4.3
2007-11-03 CVE-2007-5798 Cross-Site Scripting vulnerability in IBM Websphere Application Server
Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
network
ibm CWE-79
4.3
2007-09-12 CVE-2007-4833 Unspecified vulnerability in IBM WebSphere Application Server Edge Component
Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK44789.
network
low complexity
ibm
5.0
2007-06-19 CVE-2007-3265 Cross-Site Scripting vulnerability in Websphere Application Server
Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm
4.3
2007-06-19 CVE-2007-3264 Unspecified vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors.
network
low complexity
ibm
critical
10.0
2007-06-19 CVE-2007-3263 Unspecified vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository."
network
low complexity
ibm
critical
10.0
2007-06-19 CVE-2007-3262 Unspecified vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant memory leak.
network
low complexity
ibm
7.8