« Volver al listado

CVE-2008-3236

Estado: ModificadaMedia (5)—

Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via vectors related to "previously encrypted properties" that are not encrypted.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-3236",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-07-21T16:41:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/31149",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31892",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg27007951",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www-1.ibm.com/support/docview.wss?uid=swg1PK61941",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www-1.ibm.com/support/docview.wss?uid=swg27006879",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2140",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2566",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45123",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31149",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/31892",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg27007951",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-1.ibm.com/support/docview.wss?uid=swg1PK61941",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-1.ibm.com/support/docview.wss?uid=swg27006879",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2140",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2566",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45123",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        },
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via vectors related to \"previously encrypted properties\" that are not encrypted."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad sin especificar en Wsadmin en el cmponente System Management/Repository en IBM WebSphere Application Server (WAS) 5.1 anterior a 5.1.1.19, permite a atacantes remotos obtener información sensible a través de vectores relacionados con \"propiedades previamente encriptadas\" que no están encriptadas."
    }
  ],
  "lastModified": "2026-06-16T22:55:26.357",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66DB2053-6DFD-4FF6-A6E9-444281531E24"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31419896-89F7-43A2-8B7C-3B92744BBC46"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDA0FE3E-2FB7-415D-BC64-4B5157EABB21"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "559355CF-7FA8-4D90-8393-90C912F571C9"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "355967D9-475A-49AF-A3FF-E0AC3668B289"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBE79CF3-16A3-40FB-BD7D-5D70DEB0EE09"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC04CE9C-82B4-4406-823A-69A5E13ECA49"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F6A5B3A-E57D-4574-A481-7EDA93664076"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "425890C2-FC96-4191-B512-6A3DB7BCE2D2"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BABB4A4-182D-4FB1-88AD-B6D6EDAE10C8"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0CF8ED4D-D2B6-49EC-930A-16A78E729F17"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D8219D5-94D7-4E1B-BFA9-EF786FFD2C3C"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA0C57F6-D011-47C1-B9DC-B1C3083FD28C"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F8AFDEA-237C-40CA-AFC1-ED8D212FF867"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3067F0B0-2DCD-49EB-9727-7C3C7C99A11A"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F215B48-7ED5-45EB-BD26-3D3EAD01506F"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C47D1C56-238B-414B-B2D2-D7069E42D001"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "625B5901-B0AF-4D00-BC56-525A6F72943D"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.17:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA32E836-172D-45BF-B911-9EA2B026E76C"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:5.1.1.18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79307DAB-2195-4324-AA40-A4AE98D01513"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}