Vulnerability Name: | CVE-2001-1189 (CCN-7698) | ||||||||
Assigned: | 2001-12-13 | ||||||||
Published: | 2001-12-13 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing, Thu Dec 13 2001 - 04:36:34 CST IBM WebSphere on UNIX security alert ! Source: MITRE Type: CNA CVE-2001-1189 Source: XF Type: Vendor Advisory websphere-java-plaintext-passwords(7698) Source: CCN Type: OSVDB ID: 9679 IBM WebSphere Application Server (WAS) sas.server.props Cleartext Password Disclosure Source: BUGTRAQ Type: Vendor Advisory 20011213 IBM WebSphere on UNIX security alert ! Source: BID Type: Patch, Vendor Advisory 3682 Source: CCN Type: BID-3682 IBM WebSphere JSP Root Password Disclosure Vulnerability Source: XF Type: UNKNOWN websphere-java-plaintext-passwords(7698) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |