Vulnerability Name: | CVE-2009-0899 (CCN-50882) | ||||||||
Assigned: | 2009-05-21 | ||||||||
Published: | 2009-05-21 | ||||||||
Updated: | 2018-11-08 | ||||||||
Summary: | IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-0899 Source: CCN Type: IBM APAR PK78134 VMM flag IsSecurityEnabled incorrect after migration from WMM (PK78134) Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21375859 Source: AIXAPAR Type: Vendor Advisory PK78134 Source: CCN Type: OSVDB ID: 55079 IBM WebSphere Multiple Products Migration IsSecurityEnabled Flag Unspecified Repository Information Disclosure Source: BID Type: Third Party Advisory, VDB Entry 35406 Source: CCN Type: BID-35406 IBM WebSphere Application Server 'IsSecurityEnabled' Flag Information Disclosure Vulnerability Source: XF Type: Third Party Advisory, VDB Entry websphere-issecurityenabled-info-disclosure(50882) Source: XF Type: UNKNOWN websphere-issecurityenabled-info-disclosure(50882) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |