IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
| Software | From | Fixed in |
|---|---|---|
| ibm / websphere_application_server | 3.0.2.1 | 3.0.2.1.x |
| ibm / websphere_application_server | 3.5 | 3.5.x |
| ibm / websphere_application_server | 3.5.2 | 3.5.2.x |
| ibm / websphere_application_server | 3.0.2.2 | 3.0.2.2.x |
| ibm / websphere_application_server | 3.0 | 3.0.x |
| ibm / websphere_application_server | 3.5.1 | 3.5.1.x |
| ibm / websphere_application_server | 3.5.3 | 3.5.3.x |
| ibm / websphere_application_server | 3.0.2.3 | 3.0.2.3.x |
| ibm / websphere_application_server | 3.0.2.4 | 3.0.2.4.x |
| ibm / websphere_application_server | 3.0.2 | 3.0.2.x |