CVE-2012-2162
IBM WebSphere Application Server < 8.0.0.0 - Sensitive Information Exposure via Unencrypted HTTP Communication
Title source: llmDescription
The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74900
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21591172
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21588312
Scores
EPSS
0.0124
EPSS Percentile
66.1%
Details
CWE
CWE-310
Status
published
Products (50)
ibm/websphere_application_server
5.0
ibm/websphere_application_server
5.0.0
ibm/websphere_application_server
5.0.1
ibm/websphere_application_server
5.0.2
ibm/websphere_application_server
5.0.2.1
ibm/websphere_application_server
5.0.2.2
ibm/websphere_application_server
5.0.2.3
ibm/websphere_application_server
5.0.2.4
ibm/websphere_application_server
5.0.2.5
ibm/websphere_application_server
5.0.2.6
... and 40 more
Published
May 01, 2012
Tracked Since
Feb 18, 2026