Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-79xx-9qmj-6mhv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

EPSS

Процентиль: 67%
0.0054
Низкий

Связанные уязвимости

nvd
почти 14 лет назад

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

EPSS

Процентиль: 67%
0.0054
Низкий