4.6
CVSSv2

CVE-2001-1189

Published: 13/12/2001 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

IBM Websphere Application Server 3.5.3 and previous versions stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere application server 3.0.2.2

ibm websphere application server 3.0.2.3

ibm websphere application server 3.0.2.4

ibm websphere application server 3.5

ibm websphere application server 3.5.1

ibm websphere application server 3.0

ibm websphere application server 3.0.2.1

ibm websphere application server 3.5.3

ibm websphere application server 3.0.2

ibm websphere application server 3.5.2