CVE-2001-1189

IBM Websphere App Server <3.5.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.

References (3)

Core 3
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3682
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/7698.php
Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/245324

Scores

EPSS 0.0033
EPSS Percentile 25.1%

Details

Status published
Products (10)
ibm/websphere_application_server 3.0
ibm/websphere_application_server 3.0.2
ibm/websphere_application_server 3.0.2.1
ibm/websphere_application_server 3.0.2.2
ibm/websphere_application_server 3.0.2.3
ibm/websphere_application_server 3.0.2.4
ibm/websphere_application_server 3.5
ibm/websphere_application_server 3.5.1
ibm/websphere_application_server 3.5.2
ibm/websphere_application_server 3.5.3
Published Dec 13, 2001
Tracked Since Feb 18, 2026