CVE-2012-2162

IBM WebSphere Application Server < 8.0.0.0 - Sensitive Information Exposure via Unencrypted HTTP Communication

Title source: llm
STIX 2.1

Description

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74900
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21591172
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21588312

Scores

EPSS 0.0124
EPSS Percentile 66.1%

Details

CWE
CWE-310
Status published
Products (50)
ibm/websphere_application_server 5.0
ibm/websphere_application_server 5.0.0
ibm/websphere_application_server 5.0.1
ibm/websphere_application_server 5.0.2
ibm/websphere_application_server 5.0.2.1
ibm/websphere_application_server 5.0.2.2
ibm/websphere_application_server 5.0.2.3
ibm/websphere_application_server 5.0.2.4
ibm/websphere_application_server 5.0.2.5
ibm/websphere_application_server 5.0.2.6
... and 40 more
Published May 01, 2012
Tracked Since Feb 18, 2026