Lucene search

K
cveMitreCVE-2009-0507
HistoryFeb 26, 2009 - 4:17 p.m.

CVE-2009-0507

2009-02-2616:17:19
CWE-16
mitre
web.nvd.nist.gov
22
cve-2009-0507
ibm
websphere
process server
wps
configuration data
disclosure
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

48.6%

IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users to obtain the (1) JMSAPI, (2) ESCALATION, and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.

Affected configurations

Nvd
Node
ibmwebsphere_process_serverRange6.1.2.2
OR
ibmwebsphere_process_serverRange6.2
OR
ibmwebsphere_process_serverMatch6.1.2
OR
ibmwebsphere_process_serverMatch6.1.2.1
VendorProductVersionCPE
ibmwebsphere_process_server*cpe:2.3:a:ibm:websphere_process_server:*:*:*:*:*:*:*:*
ibmwebsphere_process_server6.1.2cpe:2.3:a:ibm:websphere_process_server:6.1.2:*:*:*:*:*:*:*
ibmwebsphere_process_server6.1.2.1cpe:2.3:a:ibm:websphere_process_server:6.1.2.1:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

48.6%

Related for CVE-2009-0507