Lucene search

K
nvd[email protected]NVD:CVE-2009-3106
HistorySep 08, 2009 - 10:30 p.m.

CVE-2009-3106

2009-09-0822:30:00
CWE-264
web.nvd.nist.gov
5

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

41.9%

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, which allows remote attackers to bypass intended access restrictions and obtain sensitive information via a crafted HTTP HEAD request to a Web Application.

Affected configurations

Nvd
Node
ibmwebsphere_application_serverMatch6.0.2
OR
ibmwebsphere_application_serverMatch6.0.2fp17
OR
ibmwebsphere_application_serverMatch6.0.2.1
OR
ibmwebsphere_application_serverMatch6.0.2.2
OR
ibmwebsphere_application_serverMatch6.0.2.3
OR
ibmwebsphere_application_serverMatch6.0.2.4
OR
ibmwebsphere_application_serverMatch6.0.2.5
OR
ibmwebsphere_application_serverMatch6.0.2.6
OR
ibmwebsphere_application_serverMatch6.0.2.7
OR
ibmwebsphere_application_serverMatch6.0.2.8
OR
ibmwebsphere_application_serverMatch6.0.2.9
OR
ibmwebsphere_application_serverMatch6.0.2.10
OR
ibmwebsphere_application_serverMatch6.0.2.11
OR
ibmwebsphere_application_serverMatch6.0.2.12
OR
ibmwebsphere_application_serverMatch6.0.2.13
OR
ibmwebsphere_application_serverMatch6.0.2.14
OR
ibmwebsphere_application_serverMatch6.0.2.15
OR
ibmwebsphere_application_serverMatch6.0.2.16
OR
ibmwebsphere_application_serverMatch6.0.2.17
OR
ibmwebsphere_application_serverMatch6.0.2.18
OR
ibmwebsphere_application_serverMatch6.0.2.19
OR
ibmwebsphere_application_serverMatch6.0.2.20
OR
ibmwebsphere_application_serverMatch6.0.2.21
OR
ibmwebsphere_application_serverMatch6.0.2.22
OR
ibmwebsphere_application_serverMatch6.0.2.23
OR
ibmwebsphere_application_serverMatch6.0.2.24
OR
ibmwebsphere_application_serverMatch6.0.2.25
OR
ibmwebsphere_application_serverMatch6.0.2.27
OR
ibmwebsphere_application_serverMatch6.0.2.28
OR
ibmwebsphere_application_serverMatch6.0.2.29
OR
ibmwebsphere_application_serverMatch6.0.2.30
OR
ibmwebsphere_application_serverMatch6.0.2.31
OR
ibmwebsphere_application_serverMatch6.0.2.32
OR
ibmwebsphere_application_serverMatch6.0.2.33
OR
ibmwebsphere_application_serverMatch6.0.2.35
VendorProductVersionCPE
ibmwebsphere_application_server6.0.2cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:fp17:*:*:*:*:*
ibmwebsphere_application_server6.0.2.1cpe:2.3:a:ibm:websphere_application_server:6.0.2.1:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.2cpe:2.3:a:ibm:websphere_application_server:6.0.2.2:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.3cpe:2.3:a:ibm:websphere_application_server:6.0.2.3:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.4cpe:2.3:a:ibm:websphere_application_server:6.0.2.4:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.5cpe:2.3:a:ibm:websphere_application_server:6.0.2.5:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.6cpe:2.3:a:ibm:websphere_application_server:6.0.2.6:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.7cpe:2.3:a:ibm:websphere_application_server:6.0.2.7:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.8cpe:2.3:a:ibm:websphere_application_server:6.0.2.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 351

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

41.9%

Related for NVD:CVE-2009-3106