IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
| Software | From | Fixed in |
|---|---|---|
| ibm / websphere_application_server | 5.0.0 | 5.0.0.x |
| ibm / websphere_application_server | 6.0.2.1 | 6.0.2.1.x |
| ibm / websphere_application_server | 6.0.2.5 | 6.0.2.5.x |
| ibm / websphere_application_server | 5.1.1 | 5.1.1.x |
| ibm / websphere_application_server | 5.1.0 | 5.1.0.x |
| ibm / websphere_application_server | 5.0.1 | 5.0.1.x |
| ibm / websphere_application_server | 6.0.2.6 | 6.0.2.6.x |
| ibm / websphere_application_server | 6.0.2.2 | 6.0.2.2.x |
| ibm / websphere_application_server | 6.0.2 | 6.0.2.x |
| ibm / websphere_application_server | 6.0.2.4 | 6.0.2.4.x |
| ibm / websphere_application_server | 6.0.2.7 | 6.0.2.7.x |
| ibm / websphere_application_server | 6.0.2.3 | 6.0.2.3.x |
| ibm / websphere_application_server | 5.0.2 | 5.0.2.x |