Vulnerabilities > IBM > Websphere Application Server > Low

DATE CVE VULNERABILITY TITLE RISK
2013-08-21 CVE-2013-4005 Cross-Site Scripting vulnerability in IBM Websphere Application Server
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified fields.
network
ibm CWE-79
3.5
2013-04-24 CVE-2013-0540 Improper Authentication vulnerability in IBM Websphere Application Server 8.5.0.0/8.5.0.1
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.
network
ibm CWE-287
3.5
2013-04-24 CVE-2013-0541 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Websphere Application Server
Buffer overflow in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Windows, when a localOS registry is used in conjunction with WebSphere Identity Manger (WIM), allows local users to cause a denial of service (daemon crash) via unspecified vectors.
1.9
2012-09-25 CVE-2012-3311 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors.
local
ibm CWE-264
3.3
2012-06-20 CVE-2012-0717 Improper Authentication vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client authentication is used, allows remote attackers to bypass X.509 client-certificate authentication via unspecified vectors.
network
high complexity
ibm CWE-287
2.6
2012-01-15 CVE-2011-5066 Information Exposure vulnerability in IBM Websphere Application Server
The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (FFDC) introspection code, which allows local users to obtain sensitive information by reading the FFDC log file.
local
low complexity
ibm CWE-200
2.1
2011-07-19 CVE-2011-1356 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Console request.
local
low complexity
ibm CWE-200
2.1
2011-03-08 CVE-2011-1307 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere Application Server
The installer in IBM WebSphere Application Server (WAS) before 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to log files via standard filesystem operations, a different vulnerability than CVE-2009-1173.
local
low complexity
ibm CWE-264
2.1
2011-03-08 CVE-2011-1310 Information Exposure vulnerability in IBM Websphere Application Server
The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which allows local users to obtain potentially sensitive information by reading these files.
local
ibm CWE-200
1.9
2010-05-17 CVE-2010-0777 Improper Input Validation vulnerability in IBM Websphere Application Server
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote attackers to obtain sensitive information by reading the retrieved file.
network
high complexity
ibm CWE-20
2.6