CVE-2006-2430

IBM WebSphere Application Server <5.0.2, <5.1.1, <=6.0.2.7 - Info D...

Title source: llm
STIX 2.1

Description

IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.

References (10)

Core 10
Core References
Patch vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=PK16492&apar=only
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/910
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1736
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20032
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/25372

Scores

EPSS 0.0284
EPSS Percentile 85.2%

Details

Status published
Products (13)
ibm/websphere_application_server 5.0.0
ibm/websphere_application_server 5.0.1
ibm/websphere_application_server 5.0.2
ibm/websphere_application_server 5.1.0
ibm/websphere_application_server 5.1.1
ibm/websphere_application_server 6.0.2
ibm/websphere_application_server 6.0.2.1
ibm/websphere_application_server 6.0.2.2
ibm/websphere_application_server 6.0.2.3
ibm/websphere_application_server 6.0.2.4
... and 3 more
Published May 17, 2006
Tracked Since Feb 18, 2026