NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
8270  CVE-2011-1312  The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.    Medium  2017-01-07  2011-04-07  View
8269  CVE-2011-1311  The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow remote authenticated users to gain privileges in opportunistic circumstances by requesting a service.    Medium  2017-01-07  2011-04-07  View
8268  CVE-2011-1310  The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which allows local users to obtain potentially sensitive information by reading these files.    1.9  Low  2017-01-07  2011-04-07  View
8267  CVE-2011-1309  The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.    7.5  High  2017-01-07  2011-04-07  View
8266  CVE-2011-1308  Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-07  2011-03-17  View

Page 16019 of 17672, showing 5 records out of 88360 total, starting on record 80091, ending on 80095

Actions