Vulnerability Name: CVE-2009-0508 (CCN-49085) Assigned: 2009-03-12 Published: 2009-03-12 Updated: 2017-08-08 Summary: The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console. Per: http://xforce.iss.net/xforce/xfdb/49085
CVSS score based on information provided by ISS. CVSS v3 Severity: 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-200 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2009-0508 Source: CCN Type: SA34283IBM WebSphere Application Server WAR File Information Disclosure Source: SECUNIA Type: Vendor Advisory34283 Source: CCN Type: SA34876IBM Tivoli Workload Scheduler WebSphere Application Server Information Disclosure Source: SECUNIA Type: Vendor Advisory34876 Source: CCN Type: IBM Security Bulletin 1376806Potential risk when using Web based applications on WebSphere Application Server (PK81387) Source: CCN Type: IBM APAR PK813877.0.0.1: Possible application source file exposure Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?rs=180&uid=swg24022456 Source: AIXAPAR Type: UNKNOWNPK81387 Source: CONFIRM Type: Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21380233 Source: CCN Type: IBM Support & downloadsWebSphere Application Server security exposures affect TWS eWAS Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21380376 Source: CONFIRM Type: Patchhttp://www-01.ibm.com/support/docview.wss?uid=swg27006876 Source: CCN Type: OSVDB ID: 52620IBM WebSphere Application Server (WAS) WAR File Handling Source Disclosure (PK81387) Source: BID Type: UNKNOWN34104 Source: CCN Type: BID-34104IBM WebSphere Application Server WAR File Information Disclosure Vulnerability Source: VUPEN Type: Patch, Vendor AdvisoryADV-2009-0704 Source: VUPEN Type: Patch, Vendor AdvisoryADV-2009-1188 Source: VUPEN Type: Patch, Vendor AdvisoryADV-2009-1464 Source: XF Type: UNKNOWNwebsphere-web-app-security-bypass(49085) Source: XF Type: UNKNOWNwebsphere-web-app-information-disclosure(49085) Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:5.1.1.19:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.3:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.5:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.7:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.9:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.11:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.15:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.17:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.19:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.21:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.23:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.25:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.27:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.29:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.31:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.0.2.33:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.9:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.11:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.13:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.15:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.17:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.19:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.21:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:5.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
ibm websphere application server 5.1.0
ibm websphere application server 5.1.1.19
ibm websphere application server 6.0.2
ibm websphere application server 6.0.2.1
ibm websphere application server 6.0.2.3
ibm websphere application server 6.0.2.5
ibm websphere application server 6.0.2.7
ibm websphere application server 6.0.2.9
ibm websphere application server 6.0.2.11
ibm websphere application server 6.0.2.15
ibm websphere application server 6.0.2.17
ibm websphere application server 6.0.2.19
ibm websphere application server 6.0.2.21
ibm websphere application server 6.0.2.23
ibm websphere application server 6.0.2.25
ibm websphere application server 6.0.2.27
ibm websphere application server 6.0.2.29
ibm websphere application server 6.0.2.31
ibm websphere application server 6.0.2.33
ibm websphere application server 6.1
ibm websphere application server 6.1.0.1
ibm websphere application server 6.1.0.2
ibm websphere application server 6.1.0.3
ibm websphere application server 6.1.0.5
ibm websphere application server 6.1.0.7
ibm websphere application server 6.1.0.9
ibm websphere application server 6.1.0.11
ibm websphere application server 6.1.0.13
ibm websphere application server 6.1.0.15
ibm websphere application server 6.1.0.17
ibm websphere application server 6.1.0.19
ibm websphere application server 6.1.0.21
ibm websphere application server 7.0
ibm websphere application server 7.0.0.1
ibm websphere application server 6.0.2
ibm websphere application server 5.1.1
ibm websphere application server 6.1
ibm websphere application server 7.0