Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm websphere application server 5.0.0 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2006-2436
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows malicious users to gain privileges.
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 5.0.2
6.4
CVSSv2
CVE-2006-2435
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and previous versions, and 5.1.1 and previous versions, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
Ibm Websphere Application Server 5.0.2
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 5.0.1
7.5
CVSSv2
CVE-2006-2432
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 5.0.2
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 5.1.1
10
CVSSv2
CVE-2006-2430
IBM WebSphere Application Server 5.0.2 and previous versions, 5.1.1 and previous versions, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows malicious users to gain privileges.
Ibm Websphere Application Server 6.0.2
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.0.2.2
Ibm Websphere Application Server 6.0.2.3
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 6.0.2.7
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 5.0.2
Ibm Websphere Application Server 6.0.2.4
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.2.6
4.3
CVSSv2
CVE-2006-2431
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and previous versions, 5.1.x prior to 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote malicious users to inject arbitrary web scri...
Ibm Websphere Application Server 5.0.2
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.2.6
Ibm Websphere Application Server 5.1.0.3
Ibm Websphere Application Server 5.1.1.11
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 6.0.2
Ibm Websphere Application Server 6.0.2.7
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 6.0.2.3
Ibm Websphere Application Server 6.0.2.4
Ibm Websphere Application Server 5.1.0.2
Ibm Websphere Application Server 5.1.0.4
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2.2
Ibm Websphere Application Server 5.1.1.10
Ibm Websphere Application Server 5.1.1.1
1 EDB exploit
10
CVSSv2
CVE-2008-4283
CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and previous versions 5.1.x versions allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Ibm Websphere Application Server 5.1.1.12
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.1.1.8
Ibm Websphere Application Server 5.1.1.9
Ibm Websphere Application Server 5.1.0.2
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 5.0.2.7
Ibm Websphere Application Server 5.0.2.6
Ibm Websphere Application Server 5.0.2.13
Ibm Websphere Application Server 5.0.2.14
Ibm Websphere Application Server 5.0.2
Ibm Websphere Application Server
Ibm Websphere Application Server 5.1.1.15
Ibm Websphere Application Server 5.1.1.18
Ibm Websphere Application Server 5.1.1.5
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 5.1.1.11
Ibm Websphere Application Server 5.0.2.3
Ibm Websphere Application Server 5.0.2.2
Ibm Websphere Application Server 5.0.2.12
6
CVSSv2
CVE-2011-1311
The Security component in IBM WebSphere Application Server (WAS) prior to 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow r...
Ibm Websphere Application Server 7.0.0.11
Ibm Websphere Application Server 7.0.0.4
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 6.0.2.29
Ibm Websphere Application Server 6.0.2.28
Ibm Websphere Application Server 5.1.1.16
Ibm Websphere Application Server 5.1.1.15
Ibm Websphere Application Server 6.0.2.17
Ibm Websphere Application Server 6.0.2.15
Ibm Websphere Application Server 6.0
Ibm Websphere Application Server 6.0.0.1
Ibm Websphere Application Server 5.1.1.4
Ibm Websphere Application Server 5.1.1.5
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 6.0.1.15
Ibm Websphere Application Server 5.0.2.2
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.1.1.17
Ibm Websphere Application Server 5.0.2.4
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 6.0.2.27
5
CVSSv2
CVE-2011-1318
Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) prior to 7.0.0.15 allows remote malicious users to cause a denial of service (memory consumption) by accessing a JSP page of an applic...
Ibm Websphere Application Server 7.0.0.11
Ibm Websphere Application Server 7.0.0.4
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 6.0.2.32
Ibm Websphere Application Server 6.0.2.29
Ibm Websphere Application Server 6.0.2.28
Ibm Websphere Application Server 5.1.1.16
Ibm Websphere Application Server 6.0.2.19
Ibm Websphere Application Server 6.0.2.17
Ibm Websphere Application Server 6.0.2.15
Ibm Websphere Application Server 6.0
Ibm Websphere Application Server 5.1.1.4
Ibm Websphere Application Server 5.1.1.5
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 5.0.2.3
Ibm Websphere Application Server 5.0.2.2
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.1.1.17
Ibm Websphere Application Server 6.0.1.1
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 6.0.2.27
6.8
CVSSv2
CVE-2010-3271
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and previous versions allow remote malicious users to hijack the authentication of administrators for req...
Ibm Websphere Application Server 7.0.0.3
Ibm Websphere Application Server 7.0.0.1
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 6.0.2.30
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 6.1.0.1
Ibm Websphere Application Server 6.1.0.2
Ibm Websphere Application Server 6.0.2.4
Ibm Websphere Application Server 6.1.0.17
Ibm Websphere Application Server 6.0.2.3
Ibm Websphere Application Server 6.0.2.13
Ibm Websphere Application Server 6.0.2.11
Ibm Websphere Application Server 6.0.2.17
Ibm Websphere Application Server 6.0.2.15
Ibm Websphere Application Server
Ibm Websphere Application Server 7.0.0.6
Ibm Websphere Application Server 7.0.0.8
Ibm Websphere Application Server 6.1.0.33
Ibm Websphere Application Server 6.0.2.32
Ibm Websphere Application Server 6.1.0.3
Ibm Websphere Application Server 6.1.0.5
Ibm Websphere Application Server 6.1.0.0
1 EDB exploit
5
CVSSv2
CVE-2011-1315
Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) prior to 7.0.0.15 allows remote malicious users to cause a denial of service (memory consumption) via network connections associated with a NULL return value from a synchronous JMS receive call.
Ibm Websphere Application Server 5.1.1.13
Ibm Websphere Application Server 6.0.2.31
Ibm Websphere Application Server 6.0.2.30
Ibm Websphere Application Server 6.0.2.32
Ibm Websphere Application Server 6.0.2.29
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2
Ibm Websphere Application Server 6.0.2.2
Ibm Websphere Application Server 6.0.2.19
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.1.1.6
Ibm Websphere Application Server 5.1.1.7
Ibm Websphere Application Server 5.1.1.4
Ibm Websphere Application Server 5.0.2.9
Ibm Websphere Application Server 5.0.2.8
Ibm Websphere Application Server 5.0.2.3
Ibm Websphere Application Server 5.0.2.2
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 6.0.1.3
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.0.1.1
Ibm Websphere Application Server 3.5.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »