Vulnerability Name:

CVE-2008-3236 (CCN-45123)

Assigned:2008-07-21
Published:2008-07-21
Updated:2017-08-08
Summary:Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via vectors related to "previously encrypted properties" that are not encrypted.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-noinfo
CWE-310
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2008-3236

Source: CCN
Type: SA31149
IBM WebSphere Application Server Unspecified Vulnerability

Source: SECUNIA
Type: Vendor Advisory
31149

Source: CCN
Type: SA31892
WebSphere Application Server Unspecified Vulnerability

Source: SECUNIA
Type: UNKNOWN
31892

Source: CCN
Type: IBM Support & downloads
Fix list for IBM WebSphere Application Server version 6.1

Source: CONFIRM
Type: UNKNOWN
http://www-01.ibm.com/support/docview.wss?uid=swg27007951

Source: AIXAPAR
Type: UNKNOWN
PK61941

Source: CONFIRM
Type: UNKNOWN
http://www-1.ibm.com/support/docview.wss?uid=swg27006879

Source: CCN
Type: OSVDB ID: 47266
IBM WebSphere Application Server (WAS) System Management/Repository Component Wsadmin Unspecified Issue

Source: VUPEN
Type: UNKNOWN
ADV-2008-2140

Source: VUPEN
Type: UNKNOWN
ADV-2008-2566

Source: XF
Type: UNKNOWN
websphere-wsadmin-information-disclosure(45123)

Source: XF
Type: UNKNOWN
websphere-wsadmin-information-disclosure(45123)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.8:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.9:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.10:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.11:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.12:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.13:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.14:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.15:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.16:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.17:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1.18:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:5.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm websphere application server 5.1.0
    ibm websphere application server 5.1.1
    ibm websphere application server 5.1.1.1
    ibm websphere application server 5.1.1.2
    ibm websphere application server 5.1.1.3
    ibm websphere application server 5.1.1.4
    ibm websphere application server 5.1.1.5
    ibm websphere application server 5.1.1.6
    ibm websphere application server 5.1.1.7
    ibm websphere application server 5.1.1.8
    ibm websphere application server 5.1.1.9
    ibm websphere application server 5.1.1.10
    ibm websphere application server 5.1.1.11
    ibm websphere application server 5.1.1.12
    ibm websphere application server 5.1.1.13
    ibm websphere application server 5.1.1.14
    ibm websphere application server 5.1.1.15
    ibm websphere application server 5.1.1.16
    ibm websphere application server 5.1.1.17
    ibm websphere application server 5.1.1.18
    ibm websphere application server 6.0.2
    ibm websphere application server 5.1.1
    ibm websphere application server 6.1