Vulnerabilities > IBM > Websphere Application Server > 6.1.0.7

DATE CVE VULNERABILITY TITLE RISK
2007-06-26 CVE-2007-3397 Information Disclosure vulnerability in IBM WebSphere Application Server Closed Connection
The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.
network
low complexity
ibm
5.0
2007-06-19 CVE-2007-3265 Cross-Site Scripting vulnerability in Websphere Application Server
Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm
4.3
2007-06-19 CVE-2007-3264 Unspecified vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors.
network
low complexity
ibm
critical
10.0
2007-06-19 CVE-2007-3263 Unspecified vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository."
network
low complexity
ibm
critical
10.0
2007-06-19 CVE-2007-3262 Unspecified vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant memory leak.
network
low complexity
ibm
7.8