CVE Vulnerabilities

CVE-2009-0899

Published: Jun 03, 2009 | Modified: Nov 08, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Integrated_solutions_console Ibm 6.0.1 (including) 6.0.1 (including)
Websphere_application_server Ibm 6.1 (including) 6.1.0.24 (including)
Websphere_application_server Ibm 7.0 (including) 7.0.0.4 (including)
Websphere_portal Ibm 5.1 (including) 6.0.0.0 (excluding)

References