CVE-2008-5411
https://notcve.org/view.php?id=CVE-2008-5411
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network. IBM WebSphere Application Server (WAS) 7 y versiones anteriores 7.0.0.1 que envía tráfico SSL sobre "TCP inseguro", el cual hace más fácil para usuarios remotos obtener información sensible, rastreando la red. • http://secunia.com/advisories/33022 http://www-01.ibm.com/support/docview.wss?uid=swg27014463 http://www-1.ibm.com/support/docview.wss?uid=swg1PK74777 http://www.securityfocus.com/bid/32679 http://www.vupen.com/english/advisories/2008/3370 https://exchange.xforce.ibmcloud.com/vulnerabilities/47135 • CWE-310: Cryptographic Issues •
CVE-2008-4678
https://notcve.org/view.php?id=CVE-2008-4678
The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure." El método HTTP_Request_Parser en el componente HTTP Transport en IBM WebSphere Application Server (WAS) v6.0.2 anterior a v6.0.2.31, permite a atacantes remotos provocar una denegación de servicio (Finalización incorrecta del controlador OC4 y cuelgue de aplicación) a través de una cabecera HTTP Host larga, relacionado con "storage overlay (superposición de almacenamiento)" sobre la pila y "parse failure. (fallo de validación)" • http://secunia.com/advisories/32296 http://www-01.ibm.com/support/docview.wss?uid=swg27006876 http://www-1.ibm.com/support/docview.wss?uid=swg1PK69371 http://www.securityfocus.com/bid/31839 http://www.vupen.com/english/advisories/2008/2871 https://exchange.xforce.ibmcloud.com/vulnerabilities/45993 • CWE-399: Resource Management Errors •
CVE-2008-4679
https://notcve.org/view.php?id=CVE-2008-4679
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate. El componente Web Services Security en IBM WebSphere Application Server (WAS) v6.0.2 anterior a v6.0.2.31 y v6.1 anterior a v6.1.0.19, cuando el Certificate Store Collections está configurado para usar las Certificate Revocation Lists (CRL), no llama al método setRevocationEnabled en el objeto PKIXBuilderParameters, que previene el "Java security method" desde la validación del estado de revocación de lso certificados X.509 y permite a atacantes remotos saltarse las restricciones de acceso establecidas a través de un mensaje SOAP con un certificado revocado. • http://secunia.com/advisories/32296 http://www-01.ibm.com/support/docview.wss?uid=swg27006876 http://www-01.ibm.com/support/docview.wss?uid=swg27007951 http://www-1.ibm.com/support/docview.wss?uid=swg1PK61258 http://www.securityfocus.com/bid/31839 http://www.vupen.com/english/advisories/2008/2871 https://exchange.xforce.ibmcloud.com/vulnerabilities/46002 • CWE-287: Improper Authentication •
CVE-2008-4111
https://notcve.org/view.php?id=CVE-2008-4111
Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when the FileServing feature is enabled, has unknown impact and attack vectors. Vulnerabilidad sin especificar en Servlet Engine/Web Container en IBM WebSphere Application Server (WAS) 6.1 anterior a 6.1.0.19, cuando la opción FileServing está activada, tiene un impacto y vectores de ataque desconocidos. • http://secunia.com/advisories/31892 http://secunia.com/advisories/32296 http://www-01.ibm.com/support/docview.wss?uid=swg27006876 http://www-01.ibm.com/support/docview.wss?uid=swg27007951 http://www-1.ibm.com/support/docview.wss?uid=swg1PK64302 http://www.securityfocus.com/bid/31186 http://www.securityfocus.com/bid/31839 http://www.vupen.com/english/advisories/2008/2566 http://www.vupen.com/english/advisories/2008/2871 https://exchange.xforce.ibmcloud.com/vulnerabilities/4512 •
CVE-2008-3423
https://notcve.org/view.php?id=CVE-2008-3423
IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors. IBM WebSphere Portal 5.1 hasta la 6.1.0.0 permite a atacantes remotos saltarse la autenticación y obtener acceso administrativo a través de vectores no especificados. • http://secunia.com/advisories/31443 http://www-1.ibm.com/support/docview.wss?uid=swg1PK67104 http://www.securityfocus.com/bid/30500 http://www.securitytracker.com/id?1020712 http://www.vupen.com/english/advisories/2008/2405 https://exchange.xforce.ibmcloud.com/vulnerabilities/44264 • CWE-264: Permissions, Privileges, and Access Controls •