CVE Vulnerabilities

CVE-2009-0506

Published: Feb 25, 2009 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.

Affected Software

Name Vendor Start Version End Version
Websphere_application_server Ibm 5.1.0 (including) 5.1.0 (including)
Websphere_application_server Ibm 6.0.2 (including) 6.0.2 (including)
Websphere_application_server Ibm 6.0.2.4 (including) 6.0.2.4 (including)
Websphere_application_server Ibm 6.0.2.6 (including) 6.0.2.6 (including)
Websphere_application_server Ibm 6.0.2.8 (including) 6.0.2.8 (including)
Websphere_application_server Ibm 6.0.2.10 (including) 6.0.2.10 (including)
Websphere_application_server Ibm 6.0.2.12 (including) 6.0.2.12 (including)
Websphere_application_server Ibm 6.0.2.14 (including) 6.0.2.14 (including)
Websphere_application_server Ibm 6.0.2.16 (including) 6.0.2.16 (including)
Websphere_application_server Ibm 6.0.2.18 (including) 6.0.2.18 (including)
Websphere_application_server Ibm 6.0.2.20 (including) 6.0.2.20 (including)
Websphere_application_server Ibm 6.0.2.22 (including) 6.0.2.22 (including)
Websphere_application_server Ibm 6.0.2.24 (including) 6.0.2.24 (including)

References