{"api_version":"1","generated_at":"2026-07-23T10:23:12+00:00","cve":"CVE-2010-0563","urls":{"html":"https://cve.report/CVE-2010-0563","api":"https://cve.report/api/cve/CVE-2010-0563.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0563","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0563"},"summary":{"title":"CVE-2010-0563","description":"The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-02-08 21:30:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/38122","name":"http://www.securityfocus.com/bid/38122","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM WebSphere Application Server 'Requires SSL' Option Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/38425","name":"http://secunia.com/advisories/38425","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"WebSphere Application Server \"Requires SSL\" Option Security Issue - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21417839","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21417839","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://www.osvdb.org/62140","name":"http://www.osvdb.org/62140","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PM00610","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1PM00610","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://securitytracker.com/id?1023551","name":"http://securitytracker.com/id?1023551","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM WebSphere Application Server Single Signon \"Requires SSL\" Option May Not Be Honored - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0563","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0563","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"563","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"563","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"7.0.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"563","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"7.0.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"563","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"7.0.0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"563","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"7.0.0.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"563","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"7.0.0.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:52:19.366Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1023551","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1023551"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21417839"},{"name":"PM00610","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PM00610"},{"name":"38122","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/38122"},{"name":"38425","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38425"},{"name":"62140","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/62140"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-02-08T21:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1023551","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1023551"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21417839"},{"name":"PM00610","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PM00610"},{"name":"38122","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/38122"},{"name":"38425","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38425"},{"name":"62140","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/62140"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-0563","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1023551","refsource":"SECTRACK","url":"http://securitytracker.com/id?1023551"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21417839","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21417839"},{"name":"PM00610","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PM00610"},{"name":"38122","refsource":"BID","url":"http://www.securityfocus.com/bid/38122"},{"name":"38425","refsource":"SECUNIA","url":"http://secunia.com/advisories/38425"},{"name":"62140","refsource":"OSVDB","url":"http://www.osvdb.org/62140"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-0563","datePublished":"2010-02-08T21:00:00.000Z","dateReserved":"2010-02-08T00:00:00.000Z","dateUpdated":"2024-09-17T00:02:32.927Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-02-08 21:30:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:*","matchCriteriaId":"B0905C80-A1BA-49CD-90CA-9270ECC3940C"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:*","matchCriteriaId":"B108457A-50DC-4432-9E30-98ADBEBF2389"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:7.0.0.3:*:*:*:*:*:*:*","matchCriteriaId":"0661F4A0-A520-4443-B19D-6885920ADFE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:7.0.0.5:*:*:*:*:*:*:*","matchCriteriaId":"9BFBDE57-3895-4841-B23C-06336A7016EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:7.0.0.7:*:*:*:*:*:*:*","matchCriteriaId":"30B7A7B9-FCD1-4509-93CF-C5B736B04F4B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:7.0.0.8:*:*:*:*:*:*:*","matchCriteriaId":"C93D1CE2-1772-44C0-A8CB-73E9AA1AF6B8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"563","Ordinal":"1","Title":"CVE-2010-0563","CVE":"CVE-2010-0563","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"563","Ordinal":"1","NoteData":"The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.","Type":"Description","Title":"CVE-2010-0563"},{"CveYear":"2010","CveId":"563","Ordinal":"2","NoteData":"2010-02-08","Type":"Other","Title":"Published"}]}}}