CVE Vulnerabilities

CVE-2006-2430

Published: May 17, 2006 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.

Affected Software

Name Vendor Start Version End Version
Websphere_application_server Ibm 5.0.0 (including) 5.0.0 (including)
Websphere_application_server Ibm 5.0.1 (including) 5.0.1 (including)
Websphere_application_server Ibm 5.0.2 (including) 5.0.2 (including)
Websphere_application_server Ibm 5.1.0 (including) 5.1.0 (including)
Websphere_application_server Ibm 5.1.1 (including) 5.1.1 (including)
Websphere_application_server Ibm 6.0.2 (including) 6.0.2 (including)
Websphere_application_server Ibm 6.0.2.1 (including) 6.0.2.1 (including)
Websphere_application_server Ibm 6.0.2.2 (including) 6.0.2.2 (including)
Websphere_application_server Ibm 6.0.2.3 (including) 6.0.2.3 (including)
Websphere_application_server Ibm 6.0.2.4 (including) 6.0.2.4 (including)
Websphere_application_server Ibm 6.0.2.5 (including) 6.0.2.5 (including)
Websphere_application_server Ibm 6.0.2.6 (including) 6.0.2.6 (including)
Websphere_application_server Ibm 6.0.2.7 (including) 6.0.2.7 (including)

References