Lucene search

K
cveMitreCVE-2006-2430
HistoryMay 17, 2006 - 10:06 a.m.

CVE-2006-2430

2006-05-1710:06:00
mitre
web.nvd.nist.gov
27
ibm
websphere
application server
vulnerability
plaintext
user credentials
addnode.log
attacker
privileges
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

High

EPSS

0.02

Percentile

89.0%

IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.

Affected configurations

Nvd
Node
ibmwebsphere_application_serverMatch5.0.0
OR
ibmwebsphere_application_serverMatch5.0.1
OR
ibmwebsphere_application_serverMatch5.0.2
OR
ibmwebsphere_application_serverMatch5.1.0
OR
ibmwebsphere_application_serverMatch5.1.1
OR
ibmwebsphere_application_serverMatch6.0.2
OR
ibmwebsphere_application_serverMatch6.0.2.1
OR
ibmwebsphere_application_serverMatch6.0.2.2
OR
ibmwebsphere_application_serverMatch6.0.2.3
OR
ibmwebsphere_application_serverMatch6.0.2.4
OR
ibmwebsphere_application_serverMatch6.0.2.5
OR
ibmwebsphere_application_serverMatch6.0.2.6
OR
ibmwebsphere_application_serverMatch6.0.2.7
VendorProductVersionCPE
ibmwebsphere_application_server5.0.0cpe:2.3:a:ibm:websphere_application_server:5.0.0:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.1cpe:2.3:a:ibm:websphere_application_server:5.0.1:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.2cpe:2.3:a:ibm:websphere_application_server:5.0.2:*:*:*:*:*:*:*
ibmwebsphere_application_server5.1.0cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*
ibmwebsphere_application_server5.1.1cpe:2.3:a:ibm:websphere_application_server:5.1.1:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.1cpe:2.3:a:ibm:websphere_application_server:6.0.2.1:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.2cpe:2.3:a:ibm:websphere_application_server:6.0.2.2:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.3cpe:2.3:a:ibm:websphere_application_server:6.0.2.3:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.4cpe:2.3:a:ibm:websphere_application_server:6.0.2.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

High

EPSS

0.02

Percentile

89.0%

Related for CVE-2006-2430