CVE-2006-2430 (GCVE-0-2006-2430)
Vulnerability from cvelistv5
Published
2006-05-17 10:00
Modified
2024-08-07 17:51
Severity ?
CWE
  • n/a
Summary
IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
References
cve@mitre.org http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html Patch
cve@mitre.org http://secunia.com/advisories/20032 Patch, Vendor Advisory
cve@mitre.org http://securityreason.com/securityalert/910
cve@mitre.org http://www-1.ibm.com/support/docview.wss?rs=0&dc=DB550&q1=PK16492&uid=swg1PK22416&loc=en_US&cs=utf-8&lang= Patch
cve@mitre.org http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24011773 Patch
cve@mitre.org http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012009 Patch
cve@mitre.org http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012064 Patch
cve@mitre.org http://www-1.ibm.com/support/search.wss?rs=0&q=PK16492&apar=only Patch
cve@mitre.org http://www.osvdb.org/25372
cve@mitre.org http://www.vupen.com/english/advisories/2006/1736
af854a3a-2127-422b-91ae-364da2661108 http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html Patch
af854a3a-2127-422b-91ae-364da2661108 http://secunia.com/advisories/20032 Patch, Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108 http://securityreason.com/securityalert/910
af854a3a-2127-422b-91ae-364da2661108 http://www-1.ibm.com/support/docview.wss?rs=0&dc=DB550&q1=PK16492&uid=swg1PK22416&loc=en_US&cs=utf-8&lang= Patch
af854a3a-2127-422b-91ae-364da2661108 http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24011773 Patch
af854a3a-2127-422b-91ae-364da2661108 http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012009 Patch
af854a3a-2127-422b-91ae-364da2661108 http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012064 Patch
af854a3a-2127-422b-91ae-364da2661108 http://www-1.ibm.com/support/search.wss?rs=0&q=PK16492&apar=only Patch
af854a3a-2127-422b-91ae-364da2661108 http://www.osvdb.org/25372
af854a3a-2127-422b-91ae-364da2661108 http://www.vupen.com/english/advisories/2006/1736
Impacted products
Vendor Product Version
n/a n/a Version: n/a
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-07T17:51:04.450Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "PK16492",
            "tags": [
              "vendor-advisory",
              "x_refsource_AIXAPAR",
              "x_transferred"
            ],
            "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=PK16492\u0026apar=only"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012064"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012009"
          },
          {
            "name": "PK22416",
            "tags": [
              "vendor-advisory",
              "x_refsource_AIXAPAR",
              "x_transferred"
            ],
            "url": "http://www-1.ibm.com/support/docview.wss?rs=0\u0026dc=DB550\u0026q1=PK16492\u0026uid=swg1PK22416\u0026loc=en_US\u0026cs=utf-8\u0026lang="
          },
          {
            "name": "910",
            "tags": [
              "third-party-advisory",
              "x_refsource_SREASON",
              "x_transferred"
            ],
            "url": "http://securityreason.com/securityalert/910"
          },
          {
            "name": "ADV-2006-1736",
            "tags": [
              "vdb-entry",
              "x_refsource_VUPEN",
              "x_transferred"
            ],
            "url": "http://www.vupen.com/english/advisories/2006/1736"
          },
          {
            "name": "20032",
            "tags": [
              "third-party-advisory",
              "x_refsource_SECUNIA",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/20032"
          },
          {
            "name": "20060509 IBM Websphere Application Server Multiple Vulnerabilities",
            "tags": [
              "mailing-list",
              "x_refsource_BUGTRAQ",
              "x_transferred"
            ],
            "url": "http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24011773"
          },
          {
            "name": "25372",
            "tags": [
              "vdb-entry",
              "x_refsource_OSVDB",
              "x_transferred"
            ],
            "url": "http://www.osvdb.org/25372"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "n/a",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ],
      "datePublic": "2006-05-09T00:00:00",
      "descriptions": [
        {
          "lang": "en",
          "value": "IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "n/a",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2007-02-16T10:00:00",
        "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "shortName": "mitre"
      },
      "references": [
        {
          "name": "PK16492",
          "tags": [
            "vendor-advisory",
            "x_refsource_AIXAPAR"
          ],
          "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=PK16492\u0026apar=only"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012064"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012009"
        },
        {
          "name": "PK22416",
          "tags": [
            "vendor-advisory",
            "x_refsource_AIXAPAR"
          ],
          "url": "http://www-1.ibm.com/support/docview.wss?rs=0\u0026dc=DB550\u0026q1=PK16492\u0026uid=swg1PK22416\u0026loc=en_US\u0026cs=utf-8\u0026lang="
        },
        {
          "name": "910",
          "tags": [
            "third-party-advisory",
            "x_refsource_SREASON"
          ],
          "url": "http://securityreason.com/securityalert/910"
        },
        {
          "name": "ADV-2006-1736",
          "tags": [
            "vdb-entry",
            "x_refsource_VUPEN"
          ],
          "url": "http://www.vupen.com/english/advisories/2006/1736"
        },
        {
          "name": "20032",
          "tags": [
            "third-party-advisory",
            "x_refsource_SECUNIA"
          ],
          "url": "http://secunia.com/advisories/20032"
        },
        {
          "name": "20060509 IBM Websphere Application Server Multiple Vulnerabilities",
          "tags": [
            "mailing-list",
            "x_refsource_BUGTRAQ"
          ],
          "url": "http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24011773"
        },
        {
          "name": "25372",
          "tags": [
            "vdb-entry",
            "x_refsource_OSVDB"
          ],
          "url": "http://www.osvdb.org/25372"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "cve@mitre.org",
          "ID": "CVE-2006-2430",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "n/a",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "n/a"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "n/a"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "n/a"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "PK16492",
              "refsource": "AIXAPAR",
              "url": "http://www-1.ibm.com/support/search.wss?rs=0\u0026q=PK16492\u0026apar=only"
            },
            {
              "name": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012064",
              "refsource": "CONFIRM",
              "url": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012064"
            },
            {
              "name": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012009",
              "refsource": "CONFIRM",
              "url": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012009"
            },
            {
              "name": "PK22416",
              "refsource": "AIXAPAR",
              "url": "http://www-1.ibm.com/support/docview.wss?rs=0\u0026dc=DB550\u0026q1=PK16492\u0026uid=swg1PK22416\u0026loc=en_US\u0026cs=utf-8\u0026lang="
            },
            {
              "name": "910",
              "refsource": "SREASON",
              "url": "http://securityreason.com/securityalert/910"
            },
            {
              "name": "ADV-2006-1736",
              "refsource": "VUPEN",
              "url": "http://www.vupen.com/english/advisories/2006/1736"
            },
            {
              "name": "20032",
              "refsource": "SECUNIA",
              "url": "http://secunia.com/advisories/20032"
            },
            {
              "name": "20060509 IBM Websphere Application Server Multiple Vulnerabilities",
              "refsource": "BUGTRAQ",
              "url": "http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html"
            },
            {
              "name": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24011773",
              "refsource": "CONFIRM",
              "url": "http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24011773"
            },
            {
              "name": "25372",
              "refsource": "OSVDB",
              "url": "http://www.osvdb.org/25372"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
    "assignerShortName": "mitre",
    "cveId": "CVE-2006-2430",
    "datePublished": "2006-05-17T10:00:00",
    "dateReserved": "2006-05-17T00:00:00",
    "dateUpdated": "2024-08-07T17:51:04.450Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "vulnerability-lookup:meta": {
    "nvd": "{\"cve\":{\"id\":\"CVE-2006-2430\",\"sourceIdentifier\":\"cve@mitre.org\",\"published\":\"2006-05-17T10:06:00.000\",\"lastModified\":\"2025-04-03T01:03:51.193\",\"vulnStatus\":\"Deferred\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.\"}],\"metrics\":{\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:L/Au:N/C:C/I:C/A:C\",\"baseScore\":10.0,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"LOW\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"COMPLETE\",\"integrityImpact\":\"COMPLETE\",\"availabilityImpact\":\"COMPLETE\"},\"baseSeverity\":\"HIGH\",\"exploitabilityScore\":10.0,\"impactScore\":10.0,\"acInsufInfo\":false,\"obtainAllPrivilege\":true,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"NVD-CWE-Other\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:5.0.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"84200300-1985-4770-81E0-31CB2CB99DCB\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:5.0.1:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"8873A6A6-D840-48E2-AED2-BB8584E3817A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:5.0.2:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"AB3F05B9-6EE1-4838-AD41-7DD329E71E3E\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"66DB2053-6DFD-4FF6-A6E9-444281531E24\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:5.1.1:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"31419896-89F7-43A2-8B7C-3B92744BBC46\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"714C405D-1E8F-45C1-8A09-5103F0080C76\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:6.0.2.1:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"C7F31FD3-8681-4F07-9644-5CC87D512520\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:6.0.2.2:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"C2604E01-E43E-4882-8896-5E646E850286\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:6.0.2.3:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"458BAD79-958E-4665-B1F8-0D46E0C57045\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:6.0.2.4:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"0B68EE27-CC4F-4530-9DFE-D94171C45F64\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:6.0.2.5:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"AC1A723F-D685-4FE5-8938-5682A2D02155\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:6.0.2.6:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"810E5AEC-5C35-4962-B9BB-32D66290D1D2\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:ibm:websphere_application_server:6.0.2.7:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"9643B593-DADF-4F57-B41E-541C7F554A4C\"}]}]}],\"references\":[{\"url\":\"http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html\",\"source\":\"cve@mitre.org\",\"tags\":[\"Patch\"]},{\"url\":\"http://secunia.com/advisories/20032\",\"source\":\"cve@mitre.org\",\"tags\":[\"Patch\",\"Vendor Advisory\"]},{\"url\":\"http://securityreason.com/securityalert/910\",\"source\":\"cve@mitre.org\"},{\"url\":\"http://www-1.ibm.com/support/docview.wss?rs=0\u0026dc=DB550\u0026q1=PK16492\u0026uid=swg1PK22416\u0026loc=en_US\u0026cs=utf-8\u0026lang=\",\"source\":\"cve@mitre.org\",\"tags\":[\"Patch\"]},{\"url\":\"http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24011773\",\"source\":\"cve@mitre.org\",\"tags\":[\"Patch\"]},{\"url\":\"http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012009\",\"source\":\"cve@mitre.org\",\"tags\":[\"Patch\"]},{\"url\":\"http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012064\",\"source\":\"cve@mitre.org\",\"tags\":[\"Patch\"]},{\"url\":\"http://www-1.ibm.com/support/search.wss?rs=0\u0026q=PK16492\u0026apar=only\",\"source\":\"cve@mitre.org\",\"tags\":[\"Patch\"]},{\"url\":\"http://www.osvdb.org/25372\",\"source\":\"cve@mitre.org\"},{\"url\":\"http://www.vupen.com/english/advisories/2006/1736\",\"source\":\"cve@mitre.org\"},{\"url\":\"http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\"]},{\"url\":\"http://secunia.com/advisories/20032\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\",\"Vendor Advisory\"]},{\"url\":\"http://securityreason.com/securityalert/910\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://www-1.ibm.com/support/docview.wss?rs=0\u0026dc=DB550\u0026q1=PK16492\u0026uid=swg1PK22416\u0026loc=en_US\u0026cs=utf-8\u0026lang=\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\"]},{\"url\":\"http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24011773\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\"]},{\"url\":\"http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012009\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\"]},{\"url\":\"http://www-1.ibm.com/support/docview.wss?rs=180\u0026uid=swg24012064\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\"]},{\"url\":\"http://www-1.ibm.com/support/search.wss?rs=0\u0026q=PK16492\u0026apar=only\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\"]},{\"url\":\"http://www.osvdb.org/25372\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://www.vupen.com/english/advisories/2006/1736\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"}]}}"
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…