CVE-2006-2430
IBM WebSphere Application Server <5.0.2, <5.1.1, <=6.0.2.7 - Info D...
Title source: llmDescription
IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
References (10)
Core 10
Core References
Patch vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/search.wss?rs=0&q=PK16492&apar=only
Patch x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012064
Patch x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012009
Patch vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?rs=0&dc=DB550&q1=PK16492&uid=swg1PK22416&loc=en_US&cs=utf-8&lang=
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/910
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1736
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20032
Patch mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html
Patch x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24011773
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/25372
Scores
EPSS
0.0284
EPSS Percentile
85.2%
Details
Status
published
Products (13)
ibm/websphere_application_server
5.0.0
ibm/websphere_application_server
5.0.1
ibm/websphere_application_server
5.0.2
ibm/websphere_application_server
5.1.0
ibm/websphere_application_server
5.1.1
ibm/websphere_application_server
6.0.2
ibm/websphere_application_server
6.0.2.1
ibm/websphere_application_server
6.0.2.2
ibm/websphere_application_server
6.0.2.3
ibm/websphere_application_server
6.0.2.4
... and 3 more
Published
May 17, 2006
Tracked Since
Feb 18, 2026