Vulnerability Name:

CVE-2009-2093 (CCN-52393)

Assigned:2009-07-27
Published:2009-07-27
Updated:2017-08-17
Summary:SQL injection vulnerability in the console in IBM WebSphere Partner Gateway (WPG) Enterprise 6.0 before FP8, 6.1 before FP3, 6.1.1 before FP2, and 6.2 before FP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS v3 Severity:5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
5.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
5.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-89
Vulnerability Consequences:Data Manipulation
References:Source: MITRE
Type: CNA
CVE-2009-2093

Source: CCN
Type: SA36295
IBM WebSphere Partner Gateway SQL Injection Vulnerability

Source: SECUNIA
Type: UNKNOWN
36295

Source: CCN
Type: IBM Support & downloads
SQL Injection Problem with WebSphere Partner Gateway Console

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21382117

Source: AIXAPAR
Type: UNKNOWN
JR32386

Source: AIXAPAR
Type: UNKNOWN
JR32607

Source: AIXAPAR
Type: UNKNOWN
JR32608

Source: AIXAPAR
Type: UNKNOWN
JR32609

Source: AIXAPAR
Type: UNKNOWN
JR33176

Source: CCN
Type: OSVDB ID: 57035
IBM WebSphere Partner Gateway (WPG) Unspecified SQL Injection

Source: VUPEN
Type: UNKNOWN
ADV-2009-2292

Source: XF
Type: UNKNOWN
wpg-console-sql-injection(52393)

Source: XF
Type: UNKNOWN
wpg-console-sql-injection(52393)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:websphere_partner_gateway:6.0.0:*:enterprise:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_partner_gateway:6.0.0:fp7:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_partner_gateway:6.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_partner_gateway:6.1.0:*:enterprise:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_partner_gateway:6.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_partner_gateway:6.1.1:*:enterprise:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_partner_gateway:6.1.1:fp1:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_partner_gateway:6.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_partner_gateway:6.2:*:enterprise:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:websphere_partner_gateway:6.1.0::enterprise:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_partner_gateway:6.1.1::enterprise:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_partner_gateway:6.2::enterprise:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm websphere partner gateway 6.0.0
    ibm websphere partner gateway 6.0.0 fp7
    ibm websphere partner gateway 6.1.0
    ibm websphere partner gateway 6.1.0
    ibm websphere partner gateway 6.1.1
    ibm websphere partner gateway 6.1.1
    ibm websphere partner gateway 6.1.1 fp1
    ibm websphere partner gateway 6.2
    ibm websphere partner gateway 6.2
    ibm websphere partner gateway 6.1.0
    ibm websphere partner gateway 6.1.1
    ibm websphere partner gateway 6.2