IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Websphere_application_server | Ibm | 3.0 (including) | 3.0 (including) |
Websphere_application_server | Ibm | 3.0.2 (including) | 3.0.2 (including) |
Websphere_application_server | Ibm | 3.0.2.1 (including) | 3.0.2.1 (including) |
Websphere_application_server | Ibm | 3.0.2.2 (including) | 3.0.2.2 (including) |
Websphere_application_server | Ibm | 3.0.2.3 (including) | 3.0.2.3 (including) |
Websphere_application_server | Ibm | 3.0.2.4 (including) | 3.0.2.4 (including) |
Websphere_application_server | Ibm | 3.5 (including) | 3.5 (including) |
Websphere_application_server | Ibm | 3.5.1 (including) | 3.5.1 (including) |
Websphere_application_server | Ibm | 3.5.2 (including) | 3.5.2 (including) |
Websphere_application_server | Ibm | 3.5.3 (including) | 3.5.3 (including) |