CVEs (492)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML. |
IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host". |
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script. |
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/...Show more |
1Ibm 2Websphere Application Server Websphere Commerce SuiteApr 16, 2026 Sep 19, 2001 N/A· v4 N/A· v3 7.5 HIGH· v2 IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing. |
1Ibm 3Net.commerce Net.commerce Hosting ServerWebsphere Application ServerApr 16, 2026 Jul 2, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters. |
1Ibm 2Net.commerce Websphere Application ServerApr 16, 2026 Jul 2, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument. |
1Ibm 2Http Server Websphere Application ServerApr 16, 2026 Mar 13, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requ...Show more |
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header. |
IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string. |
1Ibm 1Websphere Application Server Apr 16, 2026 Jun 8, 2000 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. |
IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin. |