Vulnerability Name: | CVE-2009-0507 (CCN-48892) | ||||||||
Assigned: | 2009-02-25 | ||||||||
Published: | 2009-02-25 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users to obtain the (1) JMSAPI, (2) ESCALATION, and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-16 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-0507 Source: CCN Type: SA34249 IBM WebSphere Process Server Information Disclosure Source: SECUNIA Type: UNKNOWN 34249 Source: CCN Type: IBM Web site WebSphere Process Server Source: CCN Type: IBM Support & downloads Recommended fixes for WebSphere Process Server Source: CONFIRM Type: UNKNOWN http://www-01.ibm.com/support/docview.wss?uid=swg27015580 Source: AIXAPAR Type: Vendor Advisory JR30088 Source: CCN Type: OSVDB ID: 52531 IBM WebSphere Process Server (WPS) Admin Console Cluster Configuration File Export Information Disclosure Source: CCN Type: BID-33905 IBM WebSphere Application Server Cluster Configuration File Information Disclosure Vulnerability Source: VUPEN Type: UNKNOWN ADV-2009-0670 Source: XF Type: UNKNOWN websphere-process-server-info-disclosure(48892) Source: XF Type: UNKNOWN websphere-process-server-info-disclosure(48892) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |