CVE Vulnerabilities

CVE-2009-2743

Published: Sep 21, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.

Affected Software

NameVendorStart VersionEnd Version
Websphere_application_serverIbm6.1 (including)6.1 (including)
Websphere_application_serverIbm6.1.0.1 (including)6.1.0.1 (including)
Websphere_application_serverIbm6.1.0.2 (including)6.1.0.2 (including)
Websphere_application_serverIbm6.1.0.3 (including)6.1.0.3 (including)
Websphere_application_serverIbm6.1.0.5 (including)6.1.0.5 (including)
Websphere_application_serverIbm6.1.0.7 (including)6.1.0.7 (including)
Websphere_application_serverIbm6.1.0.9 (including)6.1.0.9 (including)
Websphere_application_serverIbm6.1.0.11 (including)6.1.0.11 (including)
Websphere_application_serverIbm6.1.0.13 (including)6.1.0.13 (including)
Websphere_application_serverIbm6.1.0.15 (including)6.1.0.15 (including)
Websphere_application_serverIbm6.1.0.17 (including)6.1.0.17 (including)
Websphere_application_serverIbm6.1.0.19 (including)6.1.0.19 (including)
Websphere_application_serverIbm6.1.0.21 (including)6.1.0.21 (including)
Websphere_application_serverIbm6.1.0.23 (including)6.1.0.23 (including)
Websphere_application_serverIbm6.1.0.25 (including)6.1.0.25 (including)

References