Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by reading a cleartext field in the resources.xml file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WebSphere Application Server (WAS) 'wsadmin scripting J2CConnectionFactory'对象信息泄露漏洞
Vulnerability Description
IBM WebSphere Application Server是一个完善的、开放的Web应用服务器,它是IBM电子商务应用架构的核心。 IBM WebSphere Application Server (WAS)中的wsadmin scripting J2CConnectionFactory对象存在敏感信息泄露漏洞。因未正确定义wsadmin scripting J2CConnectionFactory对象,远程攻击者可以通过读取resources.xml 文件中的cleartext字段发现KeyRin
CVSS Information
N/A
Vulnerability Type
N/A