CVE Vulnerabilities

CVE-2006-2430

Published: May 17, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.

Affected Software

NameVendorStart VersionEnd Version
Websphere_application_serverIbm5.0.0 (including)5.0.0 (including)
Websphere_application_serverIbm5.0.1 (including)5.0.1 (including)
Websphere_application_serverIbm5.0.2 (including)5.0.2 (including)
Websphere_application_serverIbm5.1.0 (including)5.1.0 (including)
Websphere_application_serverIbm5.1.1 (including)5.1.1 (including)
Websphere_application_serverIbm6.0.2 (including)6.0.2 (including)
Websphere_application_serverIbm6.0.2.1 (including)6.0.2.1 (including)
Websphere_application_serverIbm6.0.2.2 (including)6.0.2.2 (including)
Websphere_application_serverIbm6.0.2.3 (including)6.0.2.3 (including)
Websphere_application_serverIbm6.0.2.4 (including)6.0.2.4 (including)
Websphere_application_serverIbm6.0.2.5 (including)6.0.2.5 (including)
Websphere_application_serverIbm6.0.2.6 (including)6.0.2.6 (including)
Websphere_application_serverIbm6.0.2.7 (including)6.0.2.7 (including)

References