Skip to content
High Published: Aug 13, 2009 Modified: Apr 09, 2025

CVE-2009-2092

7.5 CVSS Score High
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Export CVE-2009-2092 Data:
Share:
Link copied!

Description

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors.

CVSS Vector Details

Attack Vector Network
Attack Complexity Low
Confidentiality P
Integrity P
Availability P

Affected Software Configurations

  • a ibm websphere_application_server 7.0 * * * * * * *
  • a ibm websphere_application_server 7.0.0.1 * * * * * * *
  • a ibm websphere_application_server 7.0.0.3 * * * * * * *
  • a ibm websphere_application_server 7.0.0.4 * * * * * * *

Weaknesses (CWE)

  • CWE-284

CVE History Timeline

Aug 14, 2009 14:13 Initial Analysis
Nov 27, 2015 18:12 Modified Analysis
Aug 17, 2017 01:30 CVE Modified
May 14, 2024 02:07 CVE Modified
Nov 21, 2024 01:04 CVE Modified