CVE Vulnerabilities

CVE-2009-2747

Published: Oct 30, 2011 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.

Affected Software

Name Vendor Start Version End Version
Websphere_application_server Ibm 6.0 (including) 6.0 (including)
Websphere_application_server Ibm 6.0.0.1 (including) 6.0.0.1 (including)
Websphere_application_server Ibm 6.0.0.2 (including) 6.0.0.2 (including)
Websphere_application_server Ibm 6.0.0.3 (including) 6.0.0.3 (including)
Websphere_application_server Ibm 6.0.1 (including) 6.0.1 (including)
Websphere_application_server Ibm 6.0.1.1 (including) 6.0.1.1 (including)
Websphere_application_server Ibm 6.0.1.2 (including) 6.0.1.2 (including)
Websphere_application_server Ibm 6.0.1.3 (including) 6.0.1.3 (including)
Websphere_application_server Ibm 6.0.1.5 (including) 6.0.1.5 (including)
Websphere_application_server Ibm 6.0.1.7 (including) 6.0.1.7 (including)
Websphere_application_server Ibm 6.0.1.9 (including) 6.0.1.9 (including)
Websphere_application_server Ibm 6.0.1.11 (including) 6.0.1.11 (including)
Websphere_application_server Ibm 6.0.1.13 (including) 6.0.1.13 (including)
Websphere_application_server Ibm 6.0.1.15 (including) 6.0.1.15 (including)
Websphere_application_server Ibm 6.0.1.17 (including) 6.0.1.17 (including)
Websphere_application_server Ibm 6.0.2 (including) 6.0.2 (including)
Websphere_application_server Ibm 6.0.2.1 (including) 6.0.2.1 (including)
Websphere_application_server Ibm 6.0.2.2 (including) 6.0.2.2 (including)
Websphere_application_server Ibm 6.0.2.3 (including) 6.0.2.3 (including)
Websphere_application_server Ibm 6.0.2.4 (including) 6.0.2.4 (including)
Websphere_application_server Ibm 6.0.2.5 (including) 6.0.2.5 (including)
Websphere_application_server Ibm 6.0.2.6 (including) 6.0.2.6 (including)
Websphere_application_server Ibm 6.0.2.7 (including) 6.0.2.7 (including)
Websphere_application_server Ibm 6.0.2.9 (including) 6.0.2.9 (including)
Websphere_application_server Ibm 6.0.2.11 (including) 6.0.2.11 (including)
Websphere_application_server Ibm 6.0.2.13 (including) 6.0.2.13 (including)
Websphere_application_server Ibm 6.0.2.15 (including) 6.0.2.15 (including)
Websphere_application_server Ibm 6.0.2.17 (including) 6.0.2.17 (including)
Websphere_application_server Ibm 6.0.2.19 (including) 6.0.2.19 (including)
Websphere_application_server Ibm 6.0.2.22 (including) 6.0.2.22 (including)
Websphere_application_server Ibm 6.0.2.23 (including) 6.0.2.23 (including)
Websphere_application_server Ibm 6.0.2.24 (including) 6.0.2.24 (including)
Websphere_application_server Ibm 6.0.2.25 (including) 6.0.2.25 (including)
Websphere_application_server Ibm 6.0.2.27 (including) 6.0.2.27 (including)
Websphere_application_server Ibm 6.0.2.28 (including) 6.0.2.28 (including)
Websphere_application_server Ibm 6.0.2.29 (including) 6.0.2.29 (including)
Websphere_application_server Ibm 6.0.2.30 (including) 6.0.2.30 (including)
Websphere_application_server Ibm 6.0.2.31 (including) 6.0.2.31 (including)
Websphere_application_server Ibm 6.0.2.32 (including) 6.0.2.32 (including)
Websphere_application_server Ibm 6.0.2.33 (including) 6.0.2.33 (including)
Websphere_application_server Ibm 6.0.2.35 (including) 6.0.2.35 (including)
Websphere_application_server Ibm 6.0.2.37 (including) 6.0.2.37 (including)

References