CVE-2010-0769

IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by reading a cleartext field in the resources.xml file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
ibmwebsphere_application_server
𝑥
≤ 6.0.2.39
ibmwebsphere_application_server
6.0
ibmwebsphere_application_server
6.0.0.2
ibmwebsphere_application_server
6.0.0.3
ibmwebsphere_application_server
6.0.1
ibmwebsphere_application_server
6.0.1.2
ibmwebsphere_application_server
6.0.2
ibmwebsphere_application_server
6.0.2.1
ibmwebsphere_application_server
6.0.2.3
ibmwebsphere_application_server
6.0.2.5
ibmwebsphere_application_server
6.0.2.7
ibmwebsphere_application_server
6.0.2.9
ibmwebsphere_application_server
6.0.2.11
ibmwebsphere_application_server
6.0.2.13
ibmwebsphere_application_server
6.0.2.15
ibmwebsphere_application_server
6.0.2.17
ibmwebsphere_application_server
6.0.2.19
ibmwebsphere_application_server
6.0.2.21
ibmwebsphere_application_server
6.0.2.23
ibmwebsphere_application_server
6.0.2.25
ibmwebsphere_application_server
6.0.2.27
ibmwebsphere_application_server
6.0.2.29
ibmwebsphere_application_server
6.0.2.31
ibmwebsphere_application_server
6.0.2.33
ibmwebsphere_application_server
6.0.2.35
ibmwebsphere_application_server
6.0.2.37
ibmwebsphere_application_server
𝑥
≤ 6.1.0.29
ibmwebsphere_application_server
6.1.0
ibmwebsphere_application_server
6.1.0.1
ibmwebsphere_application_server
6.1.0.2
ibmwebsphere_application_server
6.1.0.3
ibmwebsphere_application_server
6.1.0.5
ibmwebsphere_application_server
6.1.0.7
ibmwebsphere_application_server
6.1.0.9
ibmwebsphere_application_server
6.1.0.11
ibmwebsphere_application_server
6.1.0.13
ibmwebsphere_application_server
6.1.0.15
ibmwebsphere_application_server
6.1.0.17
ibmwebsphere_application_server
6.1.0.19
ibmwebsphere_application_server
6.1.0.21
ibmwebsphere_application_server
6.1.0.23
ibmwebsphere_application_server
6.1.0.25
ibmwebsphere_application_server
6.1.0.27
ibmwebsphere_application_server
7.0
ibmwebsphere_application_server
7.0.0.1
ibmwebsphere_application_server
7.0.0.3
ibmwebsphere_application_server
7.0.0.5
ibmwebsphere_application_server
7.0.0.7
𝑥
= Vulnerable software versions
Common Weakness Enumeration