| Vulnerability Name: | CVE-2009-1174 (CCN-49534) | ||||||||
| Assigned: | 2009-03-31 | ||||||||
| Published: | 2009-03-31 | ||||||||
| Updated: | 2016-09-07 | ||||||||
| Summary: | The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-310 | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: MITRE Type: CNA CVE-2009-1174 Source: SECUNIA Type: UNKNOWN 34131 Source: CCN Type: SA34461 IBM WebSphere Application Server Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 34461 Source: CCN Type: SA35301 IBM WebSphere Application Server Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 35301 Source: CCN Type: IBM Fix Pack 6.0.2.35 Recommended fixes for WebSphere Application Server Source: CCN Type: IBM Fix Pack 6.1.0.25 Recommended fixes for WebSphere Application Server Source: CCN Type: IBM Fix Pack 7.0.0.3 Recommended fixes for WebSphere Application Server Source: CCN Type: IBM Web Services Feature Pack Fix Pack 6.1.0.25 Fix List for Web Services Feature Pack for WebSphere Application Server V6.1 Source: AIXAPAR Type: Not Applicable PK80596 Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21384925 Source: CONFIRM Type: Patch http://www-01.ibm.com/support/docview.wss?uid=swg27006876 Source: CONFIRM Type: Patch http://www-01.ibm.com/support/docview.wss?uid=swg27014463 Source: CCN Type: OSVDB ID: 53253 IBM WebSphere Application Server (WAS) Web Services Security Component XML Digital-signature Specification Unspecified Issue Source: BID Type: Third Party Advisory, VDB Entry 34506 Source: CCN Type: BID-34506 IBM WebSphere Application Server XML Digital Signature Unspecified Security Vulnerability Source: VUPEN Type: Permissions Required ADV-2009-1464 Source: XF Type: UNKNOWN websphere-xml-signature-sec-bypass(49534) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||