CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
79162 | CVE-2015-1885 | Candidate | WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors. | Assigned (20150219) | None (candidate not yet proposed) | View | |
9112 | CVE-2004-0684 | Candidate | WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters. | Assigned (20040712) | None (candidate not yet proposed) | View | |
18540 | CVE-2006-2436 | Candidate | WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges. | Assigned (20060517) | None (candidate not yet proposed) | View | |
24517 | CVE-2007-1160 | Candidate | webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782. | Assigned (20070227) | None (candidate not yet proposed) | View | |
25863 | CVE-2007-2506 | Candidate | WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe or wsisa.dll with WService=wsbroker1/_edit.r in the PATH_INFO. | Assigned (20070503) | None (candidate not yet proposed) | View |
Page 232 of 20943, showing 5 records out of 104715 total, starting on record 1156, ending on 1160