U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Keyword (text search): cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*
  • CPE Name Search: true
There are 84 matching records.
Displaying matches 81 through 84.
Vuln ID Summary CVSS Severity
CVE-2006-2431

Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.

Published: May 17, 2006; 6:06:00 AM -0400
V3.x:(not available)
V2.0: 4.3 MEDIUM
CVE-2006-2433

Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".

Published: May 17, 2006; 6:06:00 AM -0400
V3.x:(not available)
V2.0: 10.0 HIGH
CVE-2006-2342

IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.

Published: May 12, 2006; 1:06:00 PM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2005-3498

IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.

Published: November 03, 2005; 7:02:00 PM -0500
V3.x:(not available)
V2.0: 4.3 MEDIUM