CVE-2008-5411
IBM WebSphere Application Server (WAS) <7.0.0.1 - Info Disclosure
Title source: llmDescription
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
References (6)
Core 6
Core References
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33022
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK74777
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47135
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3370
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/32679
Patch x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27014463
Scores
EPSS
0.0144
EPSS Percentile
70.5%
Details
CWE
CWE-310
Status
published
Products (1)
ibm/websphere_application_server
< 7.0
Published
Dec 10, 2008
Tracked Since
Feb 18, 2026