CVE-2009-2092
7.5
CVSS Score
High
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Link copied!
Description
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
P
Affected Software Configurations
- a ibm websphere_application_server 7.0 * * * * * * *
- a ibm websphere_application_server 7.0.0.1 * * * * * * *
- a ibm websphere_application_server 7.0.0.3 * * * * * * *
- a ibm websphere_application_server 7.0.0.4 * * * * * * *
Weaknesses (CWE)
- CWE-284
References & External Links
- http://secunia.com/advisories/34461
- http://www-01.ibm.com/support/docview.wss?uid=swg27014463
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK89385
- http://www.securityfocus.com/bid/36155
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52375
- http://secunia.com/advisories/34461
- http://www-01.ibm.com/support/docview.wss?uid=swg27014463
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK89385
- http://www.securityfocus.com/bid/36155
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52375
External Resources
CVE History Timeline
Aug 14, 2009 14:13
Initial Analysis
Nov 27, 2015 18:12
Modified Analysis
Aug 17, 2017 01:30
CVE Modified
May 14, 2024 02:07
CVE Modified
Nov 21, 2024 01:04
CVE Modified