Vulnerabilities > IBM > Websphere Application Server > Low

DATE CVE VULNERABILITY TITLE RISK
2009-02-10 CVE-2009-0437 Information Exposure vulnerability in IBM Websphere Application Server 6.0.2
The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.
1.9
2008-02-13 CVE-2008-0740 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.
local
low complexity
ibm CWE-264
2.1
2003-12-31 CVE-2003-1447 Cryptographic Issues vulnerability in IBM Websphere Application Server 4.0.4
IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
local
ibm CWE-310
1.9