CVE-2008-3236

IBM WAS 5.1 <5.1.1.19 - Info Disclosure

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via vectors related to "previously encrypted properties" that are not encrypted.

References (8)

Core 8
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27007951
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2566
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2140
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31149
Various Sources x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg27006879
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK61941
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45123
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31892

Scores

EPSS 0.0131
EPSS Percentile 67.6%

Details

CWE
CWE-310
Status published
Products (20)
ibm/websphere_application_server 5.1.0
ibm/websphere_application_server 5.1.1
ibm/websphere_application_server 5.1.1.1
ibm/websphere_application_server 5.1.1.2
ibm/websphere_application_server 5.1.1.3
ibm/websphere_application_server 5.1.1.4
ibm/websphere_application_server 5.1.1.5
ibm/websphere_application_server 5.1.1.6
ibm/websphere_application_server 5.1.1.7
ibm/websphere_application_server 5.1.1.8
... and 10 more
Published Jul 21, 2008
Tracked Since Feb 18, 2026