Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm websphere application server 5.0 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-0425
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote malicious users to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of ...
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 6.0
NA
CVE-2005-1112
IBM WebSphere Application Server 6.0 and previous versions, when sharing the document root of the web server, allows remote malicious users to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processe...
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 5.0.2.3
Ibm Websphere Application Server 5.1.1.3
Ibm Websphere Application Server 5.0.2.8
Ibm Websphere Application Server 5.1.0.4
Ibm Websphere Application Server 5.1.0.2
Ibm Websphere Application Server 5.1.1.1
Ibm Websphere Application Server 5.0.2.9
Ibm Websphere Application Server 5.0.2.6
Ibm Websphere Application Server 6.0
Ibm Websphere Application Server 5.0.2.4
Ibm Websphere Application Server 5.0.2
Ibm Websphere Application Server 5.0.2.7
1 EDB exploit
NA
CVE-2005-2091
IBM WebSphere 5.1 and WebSphere 5.0 allows remote malicious users to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes W...
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 5.1.0
NA
CVE-2006-7166
IBM WebSphere Application Server (WAS) 5.1.1.9 and previous versions allows remote malicious users to obtain JSP source code and other sensitive information via "a specific JSP URL."
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 5.0.2.11
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 5.1.1.6
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 5.0.2.3
Ibm Websphere Application Server 5.0.2.15
Ibm Websphere Application Server 5.1.1.3
Ibm Websphere Application Server 5.0.2.12
Ibm Websphere Application Server 5.0.2.8
Ibm Websphere Application Server 5.1.1.7
Ibm Websphere Application Server 5.1.0.4
Ibm Websphere Application Server 5.0.2.16
Ibm Websphere Application Server 5.1.0.2
Ibm Websphere Application Server 5.0.2.2
Ibm Websphere Application Server 5.1.1.1
NA
CVE-2008-4283
CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and previous versions 5.1.x versions allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 5.0.2.11
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 5.1.1.6
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 5.0.2.3
Ibm Websphere Application Server 5.0.2.15
Ibm Websphere Application Server 5.1.1.15
Ibm Websphere Application Server 5.1.1.3
Ibm Websphere Application Server 5.1.1.13
Ibm Websphere Application Server 5.0.2.12
Ibm Websphere Application Server 5.1.1.10
Ibm Websphere Application Server 5.0.2.8
Ibm Websphere Application Server 5.1.1.17
NA
CVE-2006-3231
Unspecified vulnerability in IBM WebSphere Application Server (WAS) prior to 6.0.2.11, when fileServingEnabled is true, allows remote malicious users to obtain JSP source code and other sensitive information via "URIs with special characters."
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 5.0.2.11
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 3.5
Ibm Websphere Application Server 5.1.1.6
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 5.0.2.3
Ibm Websphere Application Server 5.0.2.15
Ibm Websphere Application Server 6.0.2.9
Ibm Websphere Application Server 5.1.1.3
Ibm Websphere Application Server 5.0.2.12
Ibm Websphere Application Server 5.1.1.10
Ibm Websphere Application Server 6.0.2
Ibm Websphere Application Server 5.0.2.8
Ibm Websphere Application Server 3.5.2
NA
CVE-2006-3232
Unspecified vulnerability in IBM WebSphere Application Server prior to 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 5.0.2.11
Ibm Websphere Application Server 5.1.1
Ibm Websphere Application Server 3.5
Ibm Websphere Application Server 5.1.1.6
Ibm Websphere Application Server 5.1.0
Ibm Websphere Application Server 5.0.1
Ibm Websphere Application Server 5.0.2.3
Ibm Websphere Application Server 5.0.2.15
Ibm Websphere Application Server 6.0.2.9
Ibm Websphere Application Server 5.1.1.3
Ibm Websphere Application Server 5.0.2.12
Ibm Websphere Application Server 5.1.1.10
Ibm Websphere Application Server 6.0.2
Ibm Websphere Application Server 5.0.2.8
Ibm Websphere Application Server 3.5.2
NA
CVE-2011-1307
The installer in IBM WebSphere Application Server (WAS) prior to 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to log files via standard filesystem operations, a different vulnerability than CVE-2009-1173.
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.1.0.21
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 3.0.21
Ibm Websphere Application Server 6.1.7
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 6.1
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 6.1.6
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.0.3
Ibm Websphere Application Server 6.1.0.2
NA
CVE-2011-1308
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) prior to 7.0.0.15 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.1.0.21
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 3.0.21
Ibm Websphere Application Server 6.1.7
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 6.1
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 6.1.6
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.0.3
Ibm Websphere Application Server 6.1.0.2
NA
CVE-2011-1311
The Security component in IBM WebSphere Application Server (WAS) prior to 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow r...
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.1.0.21
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 3.0.21
Ibm Websphere Application Server 6.1.7
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 6.1
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 6.1.6
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.0.3
Ibm Websphere Application Server 6.1.0.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4541
CVE-2024-3080
CVE-2024-4787
log injection
CVE-2024-5967
inject
CVE-2024-30078
CVE-2024-5899
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »