NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
8278  CVE-2011-1320  The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when the Tivoli Integrated Portal / embedded WebSphere Application Server (TIP/eWAS) framework is used, does not properly delete AuthCache entries upon a logout, which might allow remote attackers to access the server by leveraging an unattended workstation.    6.8  Medium  2017-01-07  2011-03-29  View
8277  CVE-2011-1319  The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote authenticated users to cause a denial of service (memory consumption) by using a Lightweight Third-Party Authentication (LTPA) token for authentication.    Medium  2017-01-07  2011-03-30  View
49347  CVE-2009-2085  The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).    7.5  High  2017-01-07  2009-08-14  View
49166  CVE-2009-1901  The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors.    10  High  2017-01-07  2009-06-24  View
15086  CVE-2010-3738  The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.    Medium  2017-01-18  2012-01-26  View

Page 3207 of 17672, showing 5 records out of 88360 total, starting on record 16031, ending on 16035

Actions