Lucene search

K
cveMitreCVE-2009-0506
HistoryFeb 25, 2009 - 4:30 p.m.

CVE-2009-0506

2009-02-2516:30:00
mitre
web.nvd.nist.gov
38
cve-2009-0506
ibm
websphere
application server
was
vulnerabilty
csiv2 identity assertion
ejb
z/os

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.

Affected configurations

Nvd
Node
ibmwebsphere_application_serverMatch5.1.0
OR
ibmwebsphere_application_serverMatch6.0.2
OR
ibmwebsphere_application_serverMatch6.0.2.4
OR
ibmwebsphere_application_serverMatch6.0.2.6
OR
ibmwebsphere_application_serverMatch6.0.2.8
OR
ibmwebsphere_application_serverMatch6.0.2.10
OR
ibmwebsphere_application_serverMatch6.0.2.12
OR
ibmwebsphere_application_serverMatch6.0.2.14
OR
ibmwebsphere_application_serverMatch6.0.2.16
OR
ibmwebsphere_application_serverMatch6.0.2.18
OR
ibmwebsphere_application_serverMatch6.0.2.20
OR
ibmwebsphere_application_serverMatch6.0.2.22
OR
ibmwebsphere_application_serverMatch6.0.2.24
AND
ibmz\/os
VendorProductVersionCPE
ibmwebsphere_application_server5.1.0cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.4cpe:2.3:a:ibm:websphere_application_server:6.0.2.4:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.6cpe:2.3:a:ibm:websphere_application_server:6.0.2.6:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.8cpe:2.3:a:ibm:websphere_application_server:6.0.2.8:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.10cpe:2.3:a:ibm:websphere_application_server:6.0.2.10:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.12cpe:2.3:a:ibm:websphere_application_server:6.0.2.12:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.14cpe:2.3:a:ibm:websphere_application_server:6.0.2.14:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.16cpe:2.3:a:ibm:websphere_application_server:6.0.2.16:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.18cpe:2.3:a:ibm:websphere_application_server:6.0.2.18:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2009-0506