CVE-2003-1447

IBM WebSphere Advanced Server Edition 4.0.4 - Weak Password Encryption via XML Export

Title source: llm
STIX 2.1

Description

IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11245
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/310796
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6758
Exploit mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/310118
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3277

Scores

EPSS 0.0023
EPSS Percentile 14.2%

Details

CWE
CWE-310
Status published
Products (1)
ibm/websphere_application_server 4.0.4
Published Dec 31, 2003
Tracked Since Feb 18, 2026