CVE Vulnerabilities

CVE-2009-2085

Improper Authentication

Published: Aug 13, 2009 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Websphere_application_server Ibm 6.1 (including) 6.1 (including)
Websphere_application_server Ibm 6.1.0 (including) 6.1.0 (including)
Websphere_application_server Ibm 6.1.0.0 (including) 6.1.0.0 (including)
Websphere_application_server Ibm 6.1.0.1 (including) 6.1.0.1 (including)
Websphere_application_server Ibm 6.1.0.2 (including) 6.1.0.2 (including)
Websphere_application_server Ibm 6.1.0.3 (including) 6.1.0.3 (including)
Websphere_application_server Ibm 6.1.0.4 (including) 6.1.0.4 (including)
Websphere_application_server Ibm 6.1.0.5 (including) 6.1.0.5 (including)
Websphere_application_server Ibm 6.1.0.6 (including) 6.1.0.6 (including)
Websphere_application_server Ibm 6.1.0.7 (including) 6.1.0.7 (including)
Websphere_application_server Ibm 6.1.0.8 (including) 6.1.0.8 (including)
Websphere_application_server Ibm 6.1.0.9 (including) 6.1.0.9 (including)
Websphere_application_server Ibm 6.1.0.10 (including) 6.1.0.10 (including)
Websphere_application_server Ibm 6.1.0.11 (including) 6.1.0.11 (including)
Websphere_application_server Ibm 6.1.0.12 (including) 6.1.0.12 (including)
Websphere_application_server Ibm 6.1.0.13 (including) 6.1.0.13 (including)
Websphere_application_server Ibm 6.1.0.14 (including) 6.1.0.14 (including)
Websphere_application_server Ibm 6.1.0.15 (including) 6.1.0.15 (including)
Websphere_application_server Ibm 6.1.0.16 (including) 6.1.0.16 (including)
Websphere_application_server Ibm 6.1.0.17 (including) 6.1.0.17 (including)
Websphere_application_server Ibm 6.1.0.18 (including) 6.1.0.18 (including)
Websphere_application_server Ibm 6.1.0.19 (including) 6.1.0.19 (including)
Websphere_application_server Ibm 6.1.0.20 (including) 6.1.0.20 (including)
Websphere_application_server Ibm 6.1.0.21 (including) 6.1.0.21 (including)
Websphere_application_server Ibm 6.1.0.22 (including) 6.1.0.22 (including)
Websphere_application_server Ibm 6.1.0.23 (including) 6.1.0.23 (including)
Websphere_application_server Ibm 6.1.0.24 (including) 6.1.0.24 (including)
Websphere_application_server Ibm 7.0 (including) 7.0 (including)
Websphere_application_server Ibm 7.0.0.1 (including) 7.0.0.1 (including)
Websphere_application_server Ibm 7.0.0.3 (including) 7.0.0.3 (including)
Websphere_application_server Ibm 7.0.0.4 (including) 7.0.0.4 (including)

Potential Mitigations

References