Vulnerabilities > IBM > Websphere Application Server

DATE CVE VULNERABILITY TITLE RISK
2001-03-13 CVE-2001-0122 Unspecified vulnerability in IBM Http Server and Websphere Application Server
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
network
low complexity
ibm
5.0
2000-11-14 CVE-2000-0848 Unspecified vulnerability in IBM Websphere Application Server 3.0.2
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
network
low complexity
ibm
critical
10.0
2000-07-24 CVE-2000-0652 Unspecified vulnerability in IBM Websphere Application Server 2.0/3.0/3.0.21
IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.
network
low complexity
ibm
5.0
2000-06-08 CVE-2000-0497 Improper Handling of Case Sensitivity vulnerability in IBM Websphere Application Server 3.0.2
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
network
low complexity
ibm CWE-178
7.5
1999-12-02 CVE-1999-0852 Unspecified vulnerability in IBM Websphere Application Server 3.0
IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.
local
low complexity
ibm
7.2