Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2003-1447

EPSS 0.04% · P11
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2003-1447

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM WebSphere导出XML密码编码不强壮漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Websphere是由IBM公司开发和维护的商业性质WEB服务器程序。 IBM Websphere在导出配置文件时包含的密码编码不够强壮,本地攻击者可以利用这个漏洞对编码的密码轻易破解。 Websphere允许管理员导出配置文件,但是导出后包含的密码以不强壮的算法保存,如果攻击者可以获得XML配置文件,就可以方便的对密码进行解码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2003-1447

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2003-1447

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-10-23 · 66 CVEs total

CVE-2003-1438BEA Systems WebLogic Server和Express会话共享漏洞
CVE-2003-1458ttCMS / ttForum Profile.php SQL注入漏洞
CVE-2003-1457Auerswald COMsuite CTI应用程序弱默认密码漏洞
CVE-2003-1456Mike Bobbitt album.pl远程任意命令执行漏洞
CVE-2003-1444Kaspersky Antivirus (KAV)漏洞
CVE-2003-1443Kaspersky Antivirus (KAV)病毒保护绕过漏洞
CVE-2003-1442HM220dp ADSL modem WEB管理接口不安全漏洞
CVE-2003-1441Posadis DNS请求问题区远程拒绝服务漏洞
CVE-2003-1440SpamProbe远程拒绝服务漏洞
CVE-2003-1439SILC Server SSH2本地内存中密码泄露漏洞
CVE-2003-1445RARLAB FAR文件管理器缓冲区溢出漏洞
CVE-2003-1437BEA WebLogic密钥库清除文本密码存储漏洞
CVE-2003-1436Nukebrowser远程包含漏洞
CVE-2003-1435PHP-Nuke modules.php远程可获取加密后口令漏洞
CVE-2003-1434login_ldap模块未授权访问漏洞
CVE-2003-1433Epic Games Unreal Engine多用户拒绝服务攻击漏洞
CVE-2003-1432Epic Games Unreal Engine内存消耗拒绝服务攻击漏洞
CVE-2003-1431Epic Games Unreal Engine Client Unreal URL服务拒绝漏洞
CVE-2003-1430Epic Games Unreal Engine Unreal URL目录遍历漏洞
CVE-2003-1429Proxomitron Naoko缓冲区溢出漏洞

Showing top 20 of 66 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2003-1447

No comments yet


Leave a comment