CVE-2012-2162: IBM WebSphere Application Server

Medium severity, CVSS 6.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

Affected products

  • IBM WebSphere Application Server: up to and including 8.0.0.0; version 5.0 only; version 5.0.0 only; version 5.0.1 only; version 5.0.2 only; version 5.0.2.1 only; …

Published 2012-05-01. Last modified 2026-06-16.