Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m28f-w6p6-jm6w

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.

The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.

EPSS

Процентиль: 64%
0.00463
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 16 лет назад

The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.

EPSS

Процентиль: 64%
0.00463
Низкий

Дефекты

CWE-200