IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network. Vendor has released a Fixpack:
http://www-01.ibm.com/support/docview.wss?rs180&uidswg24021073
Publication date: Wed, 10 Dec 2008 06:30:00 +0000